Larva-26005

2026-08-06 • AhnlabAnalysis of the Connection Between Xctdoor and Pa…

Larva-26005 is a threat actor tracked by AhnLab's ASEC, observed distributing a backdoor called Xctdoor to users in South Korea. ASEC linked the actor's recent activity to a malware family first seen in 2020 that other researchers attributed to the Lazarus group based on a shared HTTP wrapper library, overlapping remote-access-trojan functionality, ransomware deployment, WordPress-based command-and-control infrastructure, and targeting of Korean-speaking victims; ASEC assesses the current activity is likewise linked to North Korea but tracks it separately as Larva-26005. In 2026, the group distributed C++ and Go versions of Xctdoor through installers disguised as legitimate security software and through malicious shortcut files sent in spear-phishing emails using lures on topics such as account statements, leases, contracts, and job applications, targeting both corporate and general users. Earlier activity attributed to the same actor included compromising an internet-facing web server, abusing an exposed groupware upload page to spread malware internally, and tampering with the update mechanism of a Korean enterprise resource planning product to deliver the backdoor, giving the actor remote command execution, file theft, and system-monitoring capability on infected hosts.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster