Larva-25004

2025-05-22 • AhnlabLarva-25004 (Kimsuky 연관) 그룹의 추가 인증서 악용 사례 - Nexaw…

Larva-25004 is AhnLab’s designation for a Kimsuky-linked activity group discovered while investigating malware signed with certificates stolen from Korean companies. AhnLab named and began tracking the cluster in May 2025, tracing related activity back to at least August 2023. Its targets have included South Korean public enterprises, defense organizations, research institutes, and job seekers. The group delivers executable JSE, PIF, and SCR files disguised as business documents through spear-phishing, and has also compromised an internal Bizbox Alpha messenger update server to distribute a trojanized client during automatic updates. Its toolset includes HttpSpy, Memload, HttpTroy, NikiDoor, information stealers, proxy software, and document-search utilities. Some droppers carry apparently stolen code-signing certificates, while oversized or packed payloads, randomized padding, encryption, scheduled-task persistence, and virtual-environment checks help evade analysis and maintain access.

Related Actors

Related Reports in This Cluster

Top Authors

View Larva-25004 reports only

View Larva-25004 reports only