Larva-24010 is an unknown threat actor targeting Korean VPN users with compromised installers and backdoors like MeshAgent and gs-netcat.
Analyst brief
Larva-24010 is an unknown threat actor that has been targeting Korean VPN users since at least 2023 by distributing malware through a compromised VPN service provider's website. When users download and execute the installer, systems are infected with backdoors such as MeshAgent, gs-netcat, and NKNShell, enabling remote control and data theft. Defenders should verify the integrity of VPN client applications, analyze suspicious installers, and monitor for unusual outbound network connections to detect C2 activity.
Larva-24010
unknown
The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the installer from the VPN website, malware can be installed on the system. Since at least 2023, the Larva-24010 threat actor has been targeting Korean VPN users to spread malware, ultimately installing various backdoors such as MeshAgent, gs-netcat, and NKNShell. Through this, the attacker can control infected systems where the VPN is installed and steal sensitive information stored on those systems.