Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor
ID: 4b620add-aa74-53b1-bcc3-014eaeb4f17a
STIX ID: report--4b620add-aa74-53b1-bcc3-014eaeb4f17a
Feed Name: ASEC
The Larva-24009 (HeptaX) campaign uses spear-phishing LNK attachments to run obfuscated PowerShell that drops a backdoor, maintains persistence via scheduled tasks, and deploys remote access tools (QuasarRAT, UltraVNC) along with screenshot, keylogger and credential-stealing utilities (NirSoft tools). The report enumerates C2 URL paths, sample MD5 hashes, FQDNs and download URLs, describes use of a Telegram-based notifier, and documents attacker TTPs aimed at enterprise targets in Korea and internationally during 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
