Larva-24005
2025-02-27 • Ahnlab • 일본을 노리는 Larva-24005 그룹의 피싱 메일 공격 사례
AhnLab's ASEC identified Larva-24005 as a sub-group of the Kimsuky threat group receiving support from North Korea, with the name newly assigned under AhnLab's threat-actor naming system. The group breaches poorly protected Windows servers in South Korea, in some cases exploiting the BlueKeep remote-code-execution vulnerability, and after gaining access installs the open-source RDPWrap utility to enable remote desktop connections along with a custom keylogger. Using this compromised infrastructure, Larva-24005 sets up XAMPP-based web, database, and mail-sending environments to host phishing pages and send phishing emails disguised as Zoom meeting invitations or web portal login pages impersonating services such as iCloud, OneDrive, Outlook, Naver, and Google. Its primary targets are South Korean and Japanese individuals involved with North Korea issues, including university professors researching the North Korean regime, whom it profiles through browser search history and news reading before crafting tailored spear-phishing lures. Captured keylogger data and read receipts allow the group to confirm targeting success and refine subsequent phishing operations against Korea- and Japan-based victims.
-
43
Related Actors
-
799
Related Reports