#CRAT

Malware/Tool

2026-08-06 • Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

CRAT is malware associated with attacks observed from 2020 and linked by security companies to Lazarus and other North Korea-based operations. Earlier campaigns deployed CRAT alongside an early Xctdoor variant, Hansom ransomware, and credential-stealing tools. CRAT and Xctdoor used Microsoft AppX-style installation paths and closely matching runtime code-obfuscation logic that located encrypted sections through corresponding start and end patterns. These overlaps support ASEC’s assessment that the Larva-26005 actor behind newer Xctdoor activity has operated since at least 2020, although recent operations no longer showed the ransomware component.

Tagged Reports

« Back