#Nexaweb

Incident/Operation

2024-06-19 • New North-Korean based backdoor packs a punch

Nexaweb is a software company whose apparent code-signing certificate was used in May 2024 to sign two malware droppers associated by other researchers with Kimsuky and tracked by AhnLab as Larva-25004. The files used defense-industry job descriptions as decoys, masqueraded as PDFs, and installed or downloaded a backdoor that could persist through a service or user startup key. Ownership or compromise of the certificate was not confirmed: the certificate appeared only on the malicious files, and Nexaweb had not verified whether it was genuinely theirs.

Tagged Reports

« Back