logo

Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor

ID: 4b620add-aa74-53b1-bcc3-014eaeb4f17a

STIX ID: report--4b620add-aa74-53b1-bcc3-014eaeb4f17a

Feed Name: ASEC

Threat Score
72/100

Date Published: 2026-08-02

Date Updated: 2026-08-03

Author: ATCP

...
...

The Larva-24009 (HeptaX) campaign uses spear-phishing LNK attachments to run obfuscated PowerShell that drops a backdoor, maintains persistence via scheduled tasks, and deploys remote access tools (QuasarRAT, UltraVNC) along with screenshot, keylogger and credential-stealing utilities (NirSoft tools). The report enumerates C2 URL paths, sample MD5 hashes, FQDNs and download URLs, describes use of a Telegram-based notifier, and documents attacker TTPs aimed at enterprise targets in Korea and internationally during 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.