KP

Larva-24005Larva-24005

Also known as: Larva-24005

Origin
KP
Known aliases
1

Profile

Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individuals involved with North Korea and university professors researching the regime. They exploit the BlueKeep vulnerability for initial access and utilize RDPWrap and a custom keylogger post-compromise. Phishing emails are crafted to appear as legitimate communications, often containing malicious URLs or compressed files. The actor has been observed storing phishing pages in the IIS_USER account and XAMPP home folder, although traces of these pages were later deleted.

Aliases· 1

Larva-24005

References

  1. https://asec.ahnlab.com/en/86535/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Larva-24010
Actor
Larva-208
Actor
Larva-26002
Actor
Larva‑25012
Actor
UNC2970
Actor
Lancefly
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.