Larva‑25012 is a threat actor since 2024 deploying Proxyware via fake Notepad++ installers and malicious ads.
Analyst brief
Larva‑25012 is a threat actor active since at least 2024, known for deploying Proxyware, often disguised as a fake Notepad++ installer. It primarily targets users through advertisements on free YouTube download sites and fake cracked software pages. Key TTPs include injecting Proxyware into the Windows Explorer process, using Python-based loaders for evasion, and distributing various Proxyware tools like DigitalPulse, Honeygain, and Infatica. Defenders should focus on user awareness regarding suspicious ads and fake installers, monitor for anomalous injections into Windows Explorer, and pay close attention to the network behavior of Python-based loaders.
Larva‑25012
unknown
Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows Explorer process and employs Python-based loaders to evade detection. They distribute Proxyware installers primarily through advertisements on websites offering free YouTube video downloads and fake sites for cracked software. Larva‑25012 has been active since at least 2024, distributing multiple types of Proxyware, including DigitalPulse, Honeygain, and Infatica.