logo

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

ID: c7a14e2e-d205-5128-8179-44d9ae422265

STIX ID: report--c7a14e2e-d205-5128-8179-44d9ae422265

Feed Name: ASEC

Threat Score
85/100

Date Published: 2026-08-03

Date Updated: 2026-08-06

Author: ATCP

...
...

ASEC attributes a targeted campaign by the Larva-26005 threat actor (linked to North Korea) using spear-phishing, malicious LNK files, DLL side‑loading and compromised uploads to deliver XcLoader and Xctdoor (C++ and Go variants) against Korean users; the report provides technical analysis of obfuscation/injection methods, supported C2 commands, historical linkage to CRAT and Hansom ransomware, and IoCs (MD5s, URLs, FQDNs) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.