| SYMBOL | COMMON_NAME | aka. SYNONYMS |
Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found disguised as an integrated security program in an attack case reported by Hauri in 2026.
There are currently no families associated with this actor.
| 2026-08-03
⋅
AhnLab
⋅
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) CRAT DRATzarus Larva-26005 |