#CRAT
Malware/Tool
2026-08-06 • Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
CRAT is malware associated with attacks observed from 2020 and linked by security companies to Lazarus and other North Korea-based operations. Earlier campaigns deployed CRAT alongside an early Xctdoor variant, Hansom ransomware, and credential-stealing tools. CRAT and Xctdoor used Microsoft AppX-style installation paths and closely matching runtime code-obfuscation logic that located encrypted sections through corresponding start and end patterns. These overlaps support ASEC’s assessment that the Larva-26005 actor behind newer Xctdoor activity has operated since at least 2020, although recent operations no longer showed the ransomware component.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days