Larva-24005

2025-02-27 • Ahnlab일본을 노리는 Larva-24005 그룹의 피싱 메일 공격 사례

AhnLab's ASEC identified Larva-24005 as a sub-group of the Kimsuky threat group receiving support from North Korea, with the name newly assigned under AhnLab's threat-actor naming system. The group breaches poorly protected Windows servers in South Korea, in some cases exploiting the BlueKeep remote-code-execution vulnerability, and after gaining access installs the open-source RDPWrap utility to enable remote desktop connections along with a custom keylogger. Using this compromised infrastructure, Larva-24005 sets up XAMPP-based web, database, and mail-sending environments to host phishing pages and send phishing emails disguised as Zoom meeting invitations or web portal login pages impersonating services such as iCloud, OneDrive, Outlook, Naver, and Google. Its primary targets are South Korean and Japanese individuals involved with North Korea issues, including university professors researching the North Korean regime, whom it profiles through browser search history and news reading before crafting tailored spear-phishing lures. Captured keylogger data and read receipts allow the group to confirm targeting success and refine subsequent phishing operations against Korea- and Japan-based victims.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster