SYMBOLCOMMON_NAMEaka. SYNONYMS

Larva-26005  (Back to overview)


Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found disguised as an integrated security program in an attack case reported by Hauri in 2026.


Associated Families

There are currently no families associated with this actor.


References
2026-08-03AhnLabASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
CRAT DRATzarus Larva-26005

Credits: MISP Project