{
	"id": "6c94c73d-b429-4674-8ff0-72800bdda2b5",
	"created_at": "2026-08-07T02:02:14.153252Z",
	"updated_at": "2026-08-07T02:03:36.785143Z",
	"deleted_at": null,
	"sha1_hash": "0e6937ecd0cfb6182f3da59e5d9c0c6704e95ab8",
	"title": "Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 4349410,
	"plain_text": "https://asec.ahnlab.com/en/94847/\n\nAnalysis of the Connection Between Xctdoor and Past CRAT Attack\n\nCases (Larva-26005)\n\nBy ATCP\n\nPublished: 2026-08-03 · Archived: 2026-08-07 02:00:24 UTC\n\n1. Overview\n\nAhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing\n\nXctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri\n\ndisclosed an attack case in which the malware was disguised as an integrated security program. [2]\n\nWhile analyzing the attacks and malware used by the Larva-26005 threat actors, ASEC confirmed that Xctdoor is\n\nlinked to past instances of CRAT malware distribution. CRAT was first identified in 2020 and was used in various\n\nattack cases targeting South Korean users, including spear phishing attacks and distribution via uploads to domestic\n\ncommunity sites. According to a Cisco Talos report, the malware installed the Hansom ransomware to encrypt\n\ninfected systems, and attack cases of the same type were also identified in domestic ASD logs. Security firms that\n\ninvestigated CRAT identified the threat actors as the Lazarus group, and links to other North Korea-based attack\n\ncases were also confirmed. In other words, the Larva-26005 threat actors have been active since at least 2020; while\n\nthey initially used CRAT and Xctdoor in conjunction with the Hansom ransomware attack process, they appear to\n\nbe using only Xctdoor recently.\n\nThis report first summarizes attack cases identified in 2026 that disguised themselves as security programs.\n\nAlthough the initial distribution method is unknown, the malware was installed via droppers disguised as the\n\nsecurity programs Veraport and SoftCamp. In these attacks, Xctdoor was ultimately installed, with two variants\n\nused: one written in C++ and the other in Go. As the malware is currently being distributed via LNK files, this\n\nreport also summarizes newly identified attack cases. [3] This section also covers a CRAT attack case identified in\n\nKorea, in which CRAT and an early version of Xctdoor were used alongside the Hansom ransomware. Both pieces\n\nof malware were installed simultaneously and utilize the AppX package path—which is still being exploited today\n\n—as their installation path. Furthermore, similar to Xctdoor, the obfuscated code is decrypted and executed during\n\nruntime, and the process of verifying start and end patterns before and after the obfuscated code is identical. Finally,\n\nwe summarize the connections to other threat actors based on previously known attack cases.\n\n2. 2026 Attack Cases\n\n2.1. Cases of Disguise as Security Software\n\nIn March 2026, Hauri reported on an attack case exploiting Xctdoor. While the report focused on an installer\n\ndisguised as Veraport, a variant disguised as SoftCamp was also distributed from the same address.\n\nPage 1 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 1. Malware and legitimate programs inside the compressed file\n\nWhen the compressed file is decompressed, a legitimate executable and a malicious DLL are found inside the\n\n“setup” folder. The compressed file disguised as Veraport contains Sysinternals’ ShellRunAs, renamed to “veraport-\n\nq3.Exe” to mimic Veraport. When executed, it uses DLL side-loading to load and execute a malicious dropper\n\nnamed “credui.Dll” located in the same Path. While running, it creates and executes the actual Veraport installer at\n\nthe path “%TEMP%\\veraport-q3.Exe” to disguise itself as a legitimate installation program. The SoftCamp-\n\ndisguised compressed file contains the Microsoft program “wkspbroker.Exe,” which is disguised as a SoftCamp\n\ninstaller under the file name “SCWSSPSetup.Exe”; when executed, it loads the loader malware “RADCUI.Dll.”\n\nNote that the loader malware decrypts “Setup.Dat,” located in the same directory; this is the actual legitimate\n\nSoftCamp installer.\n\nPage 2 of 21\n\nFigure 2. Veraport installer\n\nFigure 3. SoftCamp Installer\n\nhttps://asec.ahnlab.com/en/94847/\n\nPage 3 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nWhen the dropper is executed via the DLL side-loading method, it creates three files. First, the VBS launcher\n\nmalware “%PUBLIC%\\videos\\s{random}.Vbs” is executed. “S{random}.Vbs” executes the BA\n\nmalware “%PUBLIC%\\videos\\{random}.Bat,” located in the same Path. “{Random}.Bat” performs its downloader\n\nfunction while simultaneously registering the VBS downloader malware “%PUBLIC%\\videos\\p{random}.Vbs,”\n\nlocated in the same Path, in the Task Scheduler.\n\nType Path\n\nVBS Launcher %PUBLIC%\\videos\\s{random}.Vbs\n\nVBS Downloader %PUBLIC%\\videos\\{random}.Bat\n\nVBS Downloader %PUBLIC%\\videos\\p{random}.Vbs\n\nPS Launcher %PUBLIC%\\videos\\2.Ps1\n\nTable 1. Script files generated\n\n“{Random}.Bat” downloads XcLoader and Xctdoor, while “p{random}.Vbs” downloads the PowerShell script\n\n“%PUBLIC%\\videos\\2.Ps1”.\n\nDownloaded\nType Download URL\nFile\n\nEncrypted\nHxxp://hesenorm[.]Info/download/xtps\nXctdoor\nBAT\n\nDownloader Encrypted\nHxxp://hesenorm[.]Info/download/lcpy\nXcLoader\n\nVBS PowerShell\nHxxp://hesenorm[.]Info/download/pxt2\nDownloader Launcher\n\nTable 2. Download Targets\n\nThe PowerShell script “%PUBLIC%\\videos\\2.Ps1” moves the file that was downloaded with the random name—\n\nthat is, the encrypted Xctdoor—to the following Path.\n\nOriginal: C:\\Users\\Public\\Pictures\\x{random}\n\nDestination:\n\n%LOCALAPPDATA%\\Packages\\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\\Settings\\roaming.Dat\n\nIt also XOR-decodes the “l{random}” file—which is XcLoader—and moves it to the following Path.\n\nSource: C:\\Users\\Public\\Pictures\\l{random}\n\nDestination:\n\n%LOCALAPPDATA%\\Packages\\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\\Settings\\settings.Lock\n\nPage 4 of 21\n\nT downloader\n\nCreation Method\n\nDropper\n\nDropper\n\nDropper\n\nDownload\n\nDownload Path\n\n%PUBLIC%\\videos\\x{random}\n\n%PUBLIC%\\videos\\x{random}\n\n%PUBLIC%\\videos\\2.Ps1\n\nhttps://asec.ahnlab.com/en/94847/\n\nThe XOR decryption method is as follows.\n\nXOR decryption method: Decrypted_Data = (Encrypted_Data ^ 0x11 ^ ((i * i) mod 0xFF)\n\nFigure 4. Decryption routine in the PowerShell script\n\nOnce this process is complete, the following command uses RegSvr32 to run XcLoader, which creates and executes\n\na shortcut on the startup path to maintain persistence.\n\nExecution command: C:\\WINDOWS\\system32\\regsvr32.Exe /s\n\n%LOCALAPPDATA%\\Packages\\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\\Settings\\settings.Lock\n\n2.2. LNK Attack Cases\n\nAttack cases involving the Larva-26005 threat actor continue to be identified, and most of the attacks detected in\n\nour ASD logs are believed to be spear phishing attacks. LNK files are used during the Initial Intrusion phase. The\n\nLNK malware acts as a dropper; similar to the security program disguise case described above, it displays a decoy\n\ndocument file while simultaneously creating and executing three script files. The following is the decoy document\n\nPage 5 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nfile generated by the “***_Comprehensive Status Report_(Confidential)_26.4.4.LNK” malware identified in an\n\nattack case from April 2026.\n\nFigure 5. Decoy document file\n\nThe LNK malware performs command execution as follows to create VBS Launcher, BAT Downloader, and VBS\n\nDownloader; its subsequent behavior is identical to that in the example above.\n\nPage 6 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 6. PowerShell commands executed by LNK\n\nThe attacks continued in June and July 2026, and the execution of the LNK files as follows was observed in these\n\nattack cases. Based on the file names of the distributed LNK files, it appears that corporate users, in addition to\n\ngeneral users, were targeted.\n\n** Account Statement.LNK\n\n2. Jeonse Deposit Investment.LNK\n\nSummary of Lease Contract Special Provisions.LNK\n\nRefund Application 1.LNK\n\nObjection to Improper Conduct.LNK\n\nProduct Registration.LNK\n\n(RESUME)_***** Cloud \u0026 CDN Sales_***.LNK\n\nSecurity Precautions for Using *** Due to the Rise in Phishing Sites.LNK\n\n** Storyboard_v1.0_260604.LNK\n\nPREE-February 1st YIDO TT.LNK\n\nPolicy Update (4).LNK\n\nΜTorrent.LNK\n\nDisk Cleanup.LNK\n\nPage 7 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nInput Data.LNK\n\n2.3. 2024 Attack Cases\n\nASEC identified additional attack cases involving Larva-26005 threat actors targeting Korea in 2024. In one case,\n\nthe threat actors first compromised an unmanaged Windows IIS web server to install a web shell, followed by the\n\ninstallation of XcLoader and Xctdoor. In addition to installing backdoors, the threat actor also installed a tunneling\n\nprogram called Ngrok to expose systems located within a NAT environment, allowing external access. [4]\n\nFigure 7. Log showing the installation of XcLoader via a web server attack\n\nIn another case, it is presumed that the threat actor attempted an Initial Breach through the upload page of a\n\ngroupware system that was exposed to the outside. By exploiting a vulnerable file upload page, the threat actor\n\nuploaded a web shell and gained initial control over the groupware system. One characteristic of this attack case\n\nwas that the attackers modified the installation file of BeeBEEP, an open-source messenger, to insert a routine that\n\ncreates and executes Xctdoor, and then replaced the existing installation file within the groupware system with a\n\nmalicious one to spread the malware internally. [5]\n\nIn addition, the threat actor exploited a Korean ERP solution by inserting a routine into the module responsible for\n\nupdates that used the Regsvr32.Exe process to execute a malicious DLL. The DLL executed by this program was\n\nXctdoor, developed in the Go programming language.\n\n3. Malware Analysis\n\n3.2. XcLoader\n\n3.2.1. Analysis of XcLoader\n\n“Settings.Lock,” which is loaded into and executed by the RegSvr32 process via a LNK file, is an injector malware.\n\nIn the 2024 incident, the threat actor also used XcLoader to inject Xctdoor into legitimate processes. In the past,\n\ntwo variants were used: one written in Go and one in C++. XcLoader reads the Xctdoor malware file\n\nPage 8 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\n“roaming.Dat,” located in the same path, and decrypts it using the same XOR algorithm as the previous PowerShell\n\nscript.\n\nXOR decryption method: Decrypted_Data = (Encrypted_Data ^ 0x11 ^ ((i * i) mod 0xFF)\n\nIt then checks for the presence of the `settings.Ini` file in the same path. Although `settings.Ini` was not recovered\n\nin this case, the files identified in similar past cases are as follows.\n\nApplicationFrameHost.Exe\n\nRuntimebroker.Exe\n\nSihost.Exe\n\nTaskhostw.Exe\n\nExplorer.Exe\n\nIf the “settings.Ini” file exists, the process name stored as a string in that file is retrieved, and the previously\n\ndecoded roaming.Dat PE file is injected into that process. If the “settings.Ini” file does not exist, the file is injected\n\ninto the “explorer.Exe” process. During the injection process, the roaming.Dat PE file is copied into memory twice.\n\nIt then inserts shellcode to execute RsdserviceMain(), an export function of Xctdoor, and executes that shellcode.\n\nAs a result, the following five parameters are passed to the RsdserviceMain() function.\n\nParameter 1: 0\n\nParameter 2: The address of Xctdoor (roaming.Dat) to be used for process injection\n\nParameter 3: Hash value of the Xctdoor main function name (OfficeServiceMain()) (0x46903DF2)\n\nParameter 4: Address of Xctdoor (roaming.Dat) to be saved to a file (target for changing the XOR key used\n\nfor code obfuscation)\n\nParameter 5: File size of the Xctdoor (roaming.Dat) file\n\nNote that Parameter 3 is the hash value used to locate the backdoor’s main function, OfficeServiceMain().\n\n3.2.2. Code Obfuscation\n\nFrom droppers that operate via DLL side-loading to XcLoader and Xctdoor, all have their code sections subjected\n\nto obfuscation and the code section is decrypted during execution. Such a method has been consistently used since\n\npast cases.\n\nPage 9 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 8. Obfuscated and Deobfuscated Code\n\nObfuscation routines are classified into two types, both of which use the same deobfuscation routine. However, the\n\nmethod for locating the obfuscated code section differs for each type. Additionally, the signature values and\n\nobfuscation keys used to identify the obfuscated code section are set differently for each sample. Functions that\n\nhave been obfuscated call the deobfuscation routine at the beginning of execution to restore the code section before\n\nperforming their original functions. Then, just before the function ends, they call the obfuscation routine again to\n\nreturn the restored code section to its obfuscated state.\n\nThe first type uses a 10-byte signature when traversing the obfuscated code section.\n\nStructure of the encrypted code section: {Start Signature:10} {Random Data:7} {Obfuscation Code} {End\n\nSignature:10}\n\nPage 10 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 9. Deobfuscation routine of the first type\n\nIn the second type, a distinctive feature is that the start signature and end signature are separated into two distinct\n\nsegments when locating the obfuscated code section. The start signature is verified based on the first 4 bytes and the\n\nlast 4 bytes within a 14-byte range, and the end signature is verified in the same manner. The overall structure is as\n\nfollows.\n\nStructure of the encrypted code region: {Start Signature_1:4} {Intermediate Data:6} {Start Signature_2:4}\n\n{Random Data:5} {Obfuscation Code} {Random Data:1} {End Signature_1:4} {Intermediate Data:6} {End\n\nSignature_2:4}\n\nPage 11 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 10. Decryption routine for the second type of obfuscation\n\n3.3. Analysis of Xctdoor\n\n3.3.1. Xctdoor (C++)\n\nSince the injected “roaming.Dat”—i.E., Xctdoor—is loaded into memory in RAW format and cannot be executed\n\nas-is, additional memory is allocated through the RsdServiceMain() function, and the file is then reloaded as a PE\n\nimage. Once the memory loading is complete, the DLL undergoes a manual mapping process, and the\n\nDllEntryPoint() function is called. Subsequently, it locates and executes the OfficeServiceMain() function by\n\ncomparing the hash value of the “OfficeServiceMain” string—received as an argument—with the Export functions.\n\nThe `OfficeServiceMain()` function is responsible for performing the actual backdoor functions. Before executing\n\nthese functions, it modifies the obfuscation signature and key values within the backdoor PE file (passed as the\n\nfourth parameter), re-encrypts them, and saves the result as the “roaming.Dat” file. Such behavior is presumed to be\n\nintended to bypass static signature-based detection by antivirus programs by continuously altering the file’s\n\ncontents.\n\nWhen Xctdoor is executed, it checks the user’s absence status using the following three conditions. Whenever the\n\nuser’s absence status changes, it transmits the updated status information to the C\u0026C server.\n\nUser Absence Conditions (OR Conditions)\n\nScreensaver On\n\nMonitor display off\n\nSession Locked\n\nPage 12 of 21\n\nIt then connects to the C\u0026C server to receive commands from the threat actor\n\nreceives from the C2 server are as follows.\n\nCommand\n\nNumber\n\n0X10001\n\n0X10002\n\n0X10003\n\n0X10004\n\n0X10005\n\n0X10006\n\n0X10007\n\n0X10008\n\n0X1000A\n\n0X1000B\n\n0X1000C\n\n0X1000D\n\n0X1000E\n\n0X10010\n\nhttps://asec.ahnlab.com/en/94847/\n\n. The commands this backdoor\n\nDescription\n\nCreate shell session object\n\nSelect termination method when ending the shell session\n\n—1 terminates only the shell session process;\n\n0 terminates both the shell session and its child processes\n\nReceive a shell command\n\nRetrieve full drive information\n\nRetrieve\n\na list of files inside a specific folder (file name, file\n\nattributes, file size, last modified time)\n\nPreparing to download a file (or memory)\n\nFile (or memory) download in progress\n\nFile (or memory) download complete\n\n—for files, apply the desired file time and file attributes\n\n– For memory: Injection into a specific process\n\nDeleted specific file/folder and its subfolders\n\nCreate a folder at a specific Path and retrieve the list of\n\nfiles within its parent folder\n\nCancel a file (or memory) download\n\nPreparing to upload a file (transferring file size)\n\nFile Upload in Progress\n\nRetrieving system information\n\nPage 13 of 21\n\nTransmission\n\nNumber After\n\nCompletion\n\n3\n\n4\n\n5\n\nSuccess: 6\n\nFailure: 7\n\nSuccess: 6\n\nFailure: 7\n\nFile: Not\n\nsent Memory:\n\nSuccess 20\n\n5\n\n5\n\nSuccess: 8\n\nFailure: 7\n\nUploading: 9\n\nComplete: 10\n\nFailed: 7\n\n12\n\nhttps://asec.ahnlab.com/en/94847/\n\nCommand\nDescription\nNumber\n\nCommand execution with the window visible (using\n0X10011\nShellExecute)\n\nCommand execution with the window hidden (using\n0X10012\nCreateProcess)\n\n0X10015 Terminate the backdoor (including cleanup)\n\nRetrieve\n0X10016\nprocess list (PID, PPID, number of threads, process Path)\n\n0X10017 Terminate a Specific Process\n\n0X10018 Start keylogging\n\n0X10019 End keylogging\n\n0X1001A No behavior\n\n0X1001B Current communication session terminated\n\nBackdoor Forced Termination (Upon 0 Transmission /\n0X1001F\nException Occurred)\n\n0X10021 Multiple command execution (using cmd /c)\n\nConfiguration Changes\n\n(communication interval, port number, whether to\n0X10022\nperform periodic keylogging/screenshots, screenshot\n\ninterval, whether to monitor drives, etc.)\n\n0X10024 Take a screenshot immediately\n\nReset the %ALLUSERSPROFILE%\\msci.Cng file (data\n0X10025\nused in communication packet headers)\n\nStoring data after creating shared memory\n0X10026\nShared memory name: SM3:2300:402:WilStaging_01\n\n0X10027 Freeing shared memory\n\n0X10028 Retrieve the name of the currently running process\n\n0X10029 Move file/folder\n\nPage 14 of 21\n\nTransmission\n\nNumber After\n\nCompletion\n\n16\n\n16\n\n22\n\n24\n\n12\n\n26\n\n5\n\nTable 3. Commands Supported by Xctdoor\n\nWhen transmitting data, it is segmented based on the transmission numbers listed below and sent to the C2 server.\n\nTransmission Number\n\n3\n\n4\n\n5\n\n6\n\n7\n\n8\n\n9\n\n10\n\n12\n\n15\n\n16\n\n17\n\n18\n\n19\n\n20\n\n22\n\n23\n\n24\n\n25\n\n26\n\nTable 4. Numbers used by the backdoor when transmitting to the C2 server\n\n3.3.2. Xctdoor (Go)\n\nSimilar to the 2024 case, Xctdoor—developed in the Go language—was also identified. Compared to the C++\n\nvariant, this malware is virtually identical in terms of user absence monitoring conditions, command numbers, and\n\nhttps://asec.ahnlab.com/en/94847/\n\nDescription\n\nTransmission of shell command results\n\nPassing the results of the entire drive\n\nPassing a List of Files Inside a Specific Folder\n\nDownload Ready\n\nDownload/Upload Failed\n\nFile upload ready\n\nFile upload in progress\n\nFile upload complete\n\nSystem Information Transmitted\n\nUser Absence Note\n\nProcess List Transmission\n\nTransmit keylog data with every keystroke\n\nSend data whenever the clipboard content changes\n\nSend keylog data whenever the active window changes\n\nDownload and injection complete\n\nResults of multiple command executions transmitted\n\nTransmitting modified drive information\n\nSubmitting Screenshots\n\nNote When a New Drive Is Installed\n\nTransmission of the Name of the Injected Process\n\nPage 15 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\ntransmission numbers.\n\nFigure 11. Xctdoor written in Go\n\n4.1. CRAT\n\nCRAT is a backdoor malware first identified in April 2020 that was distributed through various methods, primarily\n\ntargeting users in Korea. The first detected instance of CRAT was distributed via a spear phishing attack using a\n\nHangul document with the file name “Coronavirus Response Emergency Inquiry.Hwp” that exploited the CVE-\n\n2017-8291 vulnerability. [6] Subsequently, the attack vectors were expanded to include dropping [7] or\n\ndownloading CRAT from tampered programs uploaded to Korean community sites; on Korean academic websites,\n\nthe malware in the form of Hangul documents was also uploaded disguised as documents related to\n\n“announcements.”\n\nPage 16 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 12. Example of a Hangul document spear phishing attack distributed in April 2020 using COVID-19-related\n\nthemes\n\nFigure 13. Case of distribution via a Korea community site in July 2020\n\nThe CRAT samples initially distributed were classified as CRAT due to the presence of the keyword “crat” in the\n\nPDB path; detailed analysis information can be found in the TI report. [8] CRAT is a backdoor malware that\n\ncommunicates with a C\u0026C server via the HTTP protocol and supports functions such as collecting system\n\ninformation, performing file operations, command execution, downloading additional payloads, and compressing\n\nand exfiltrating user files. Upon execution, it injects itself into a legitimate process and creates a LNK file in a path\n\nsuch as “%LOCALAPPDATA%\\Microsoft\\WindowsApps\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\\n\n\u003cRANDOM8\u003e.\u003cRANDOM3\u003e” and registers an LNK file that executes it via RegSvr32 in the Run key.\n\nCRAT is also sometimes used in conjunction with additional modules. It attempts to connect to a named pipe\n\nnamed “\\\\.\\Pipe\\ChromeUpdatePipe” and, if successful, transmits the payload; the co-installed injector module can\n\nread from that named pipe and inject the received payload into a legitimate process.\n\nPage 17 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\nFigure 14. CRAT’s mutex name\n\n4.2. Attack Cases in Korea Involving Xctdoor\n\nCRAT is known to use various plugins, including the Hansom ransomware, such as keyloggers, screen capture\n\ntools, and clipboard monitoring tools. As noted in a 2020 Cisco Talos report, cases where CRAT was installed\n\nalongside the Hansom ransomware were identified in attack cases targeting Korea. In each of these attack cases, in\n\naddition to CRAT and Hansom ransomware, an injector that injects payloads delivered via Named Pipes, as well as\n\nnumerous credential-stealing tools targeting various web browsers, were also collected.\n\nFigure 15. Hansom ransomware ransom note\n\nThreat Actor Email Address – 1: hansom2008@protonmail[.]Com\n\nThreat actor’s email address – 2: hansompay2008@yandex[.]Com\n\nPage 18 of 21\n\nThe most notable feature of the Hansom ransomware attack case is that an early version of Xctdoor was used\n\nalongside Hansom ransomware. In addition to being used simultaneously\n\nidentical. AppX package paths such as\n\n“%LOCALAPPDATA%\\microsoft\\windowsapps\\microsoft.Microsoftedge_8wekyb3d8bbwe\\” have been\n\nconsistently used, from the CRAT malware of the past to the Xctdoor variant observed in the 2026 incident.\n\nFurthermore, the CRAT used in the attack employs obfuscation in the same way as Xctdoor\n\nmalware share the same approach: they decrypt the code starting from a command that marks the beginning of the\n\nencrypted section and continue until they reach a command that marks the end.\n\nStart command 1: C7 05 … 0XE840C764\n\nStart command 2: C7 05 … 0XB988C344\n\nStart Command 3: C7 05 … 0XFFE8CC02\n\nStart Command 4: C7 05 … 0X80D43F05\n\nEnd Command 1: C7 05 … 0X81C6D232\n\nEnd Command 2: C7 05 … 0XC902D654\n\nEnd Command 3: C7 05 … 0XC8E404F0\n\nEnd Command 4: C7 05 … 0X7C01F922\n\nhttps://asec.ahnlab.com/en/94847/\n\n, the malware installation paths are also\n\n. Both pieces of\n\nFigure 16. Obfuscation routine and obfuscated start pattern\n\n4.3. Threat Actor Information\n\nRegarding the 2020 spear phishing attacks that distributed CRAT to users in Korea, East Security classified the\n\nLazarus group as the threat actor, citing the fact that the group utilizes WordPress-based websites when setting up\n\nC\u0026C servers. [9] [10] Cisco Talos also noted a connection to the Lazarus group, citing similarities in the attack\n\ntechniques—despite difficulties in obtaining Threat Actor Information—as evidence of a link to the Lazarus group.\n\nSimilarities include the use of the same HTTP Wrapper library as other malware used by the Lazarus group,\n\nPage 19 of 21\n\nhttps://asec.ahnlab.com/en/94847/\n\noverlapping RAT functionalities, the distribution of ransomware, and the use of WordPress-based websites as C\u0026C\n\nservers. Additionally, it was noted that, based on CRAT’s decoy files, the group targets Korean-speaking users.\n\nIn September 2020, QiAnXin covered a spear phishing attack carried out by Lazarus threat actors. [11] [12] One of\n\nthe C\u0026C server addresses for the downloader malware used in that attack case was “www.Fabioluciani[.]Com.”\n\nThis address is also included in a Kaspersky report on Lazarus threat actors’ attack cases targeting the defense\n\nindustry using ThreatNeedle [13] and in a Google TAG report covering an attack campaign by a threat actor\n\nbelieved to be from North Korea targeting security researchers. [14]\n\nIn the 2024 attack case, the threat actor patched a Korean ERP solution to execute malware to maintain persistence.\n\nSuch an attack method is similar to that of the Andariel threat actors, who were confirmed to have attacked\n\ndomestic ERP solutions to conduct malware distribution not only in 2017 but also in 2025. [15] ASEC has\n\nclassified this threat actor as Larva-26005 and believes there is a link to North Korea. In recently identified attacks,\n\nthe threat actor is installing XcLoader and Xctdoor; while no ransomware attacks have been confirmed recently, the\n\ncollection of information from infected systems continues.\n\n5. Conclusion\n\nThe Larva-26005 threat actors spread their malware through phishing emails using keywords such as investment,\n\nreal estate transactions, sales, and security documents; there have also been cases where the malware was disguised\n\nto appear as security software installation files. Users may download and execute these files, mistaking them for\n\ndocument files or legitimate programs; doing so can result in the installation of the XcLoader and Xctdoor\n\nbackdoors, leading to a compromise of system control. Since the threat actors install information-stealing tools in\n\naddition to the backdoors, sensitive information—such as credentials and user files—may be stolen.\n\nUsers should exercise extreme caution not only with email attachments but also with executable files from\n\nunknown sources. Also, V3 should be updated to the latest version so that malware infections can be prevented.\n\nMD5\n\n01b58f2ff2c14feed46a0768ea46686d\n\n07766e6e9d9f86775ad564a65af292c1\n\n08e19a0d516d14e564359ee111ed2586\n\n0d2e61c8a5e6280e065b61e75b848c68\n\n12391f66ee33d379108fd649a999e1a0\n\nAdditional IOCs are available on AhnLab TIP.\n\nURL\n\nhttp[:]//casinolegit[.]info/ms/beeLogo[.]webp\n\nhttp[:]//casinosec[.]info/ms/beeLogo[.]webp\n\nPage 20 of 21\n\nhttp[:]//cristiantirira[.]com/wp-content/uploads/2018/11/03-499×300[.]png\n\nhttp[:]//desk-azureft[.]info/wp-include/wpmain[.]php\n\nhttp[:]//grace2019[.]teamernst[.]net/wp-content/uploads/2011/08/student_2141-800×200[.]jpg\n\nAdditional IOCs are available on AhnLab TIP\n\nFQDN\n\ncasinolegit[.]fun\n\nhesenorm[.]info\n\nhttps://asec.ahnlab.com/en/94847/\n\n.\n\nkoramate[.]fun\n\nntsgo-corp[.]com\n\nntsgo[.]name\n\nAdditional IOCs are available on AhnLab TIP.\n\nGain access to related IOCs and detailed analysis by subscribing to\n\nbanner below.\n\nSource: https://asec.ahnlab.com/en/94847/\n\nPage 21 of 21\n\nAhnLab TIP. For subscription details, click the",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"MISPGALAXY",
		"Malpedia"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://asec.ahnlab.com/en/94847/"
	],
	"report_names": [
		"94847"
	],
	"threat_actors": [],
	"ts_created_at": 1786068134,
	"ts_updated_at": 1786068216,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/0e6937ecd0cfb6182f3da59e5d9c0c6704e95ab8.pdf",
		"text": "https://archive.orkl.eu/0e6937ecd0cfb6182f3da59e5d9c0c6704e95ab8.txt",
		"img": "https://archive.orkl.eu/0e6937ecd0cfb6182f3da59e5d9c0c6704e95ab8.jpg"
	}
}