SYMBOLCOMMON_NAMEaka. SYNONYMS

Larva-24009  (Back to overview)


Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The actor employs LNK malware to install a PowerShell backdoor and maintains persistence with remote control tools like QuasarRAT and UltraVNC. They utilize phishing emails with keywords such as “hospital survey” and “resume,” disguising malware as document files to trick users into execution. This results in the theft of sensitive information, including credentials and user files.


Associated Families

There are currently no families associated with this actor.


References
2026-08-02AhnLabASEC
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor
Quasar RAT Larva-24009

Credits: MISP Project