Larva-26005 is a confirmed threat actor distributing Xctdoor RAT in South Korea, disguised as a security tool.
Analyst brief
Larva-26005 is a confirmed threat actor distributing the Xctdoor RAT, targeting users in South Korea. The group employs deceptive TTPs by disguising the malware as an integrated security program, as observed in a 2026 attack. Defenders should monitor for suspicious software installations, especially fake security tools, and track C2 traffic associated with Xctdoor.
Larva-26005
activeunknown
Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found disguised as an integrated security program in an attack case reported by Hauri in 2026.