#Hansom
Malware/Tool
2026-08-06 • Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
Hansom is ransomware historically deployed in South Korean attacks associated with the Larva-26005 activity cluster. Earlier operations installed it alongside CRAT, credential-stealing utilities, a payload injector, and an early Xctdoor variant. The surrounding toolset used Microsoft AppX-style installation paths and runtime code-obfuscation patterns, supporting links between the older ransomware activity and later Larva-26005 operations. More recent campaigns shifted toward XcLoader and Xctdoor for initial execution, persistence, command execution, and information theft.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days