| SYMBOL | COMMON_NAME | aka. SYNONYMS |
Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The actor employs LNK malware to install a PowerShell backdoor and maintains persistence with remote control tools like QuasarRAT and UltraVNC. They utilize phishing emails with keywords such as “hospital survey” and “resume,” disguising malware as document files to trick users into execution. This results in the theft of sensitive information, including credentials and user files.
There are currently no families associated with this actor.
| 2026-08-02
⋅
AhnLab
⋅
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor Quasar RAT Larva-24009 |