Larva-24009Larva-24009
Also known as: Larva-24009
Known aliases
1
Profile
Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The actor employs LNK malware to install a PowerShell backdoor and maintains persistence with remote control tools like QuasarRAT and UltraVNC. They utilize phishing emails with keywords such as “hospital survey” and “resume,” disguising malware as document files to trick users into execution. This results in the theft of sensitive information, including credentials and user files.
Aliases· 1
Larva-24009