Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor — Threadlinqs Intelligence
As of 2026-08-03, Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor is a high-severity malware threat attributed to Larva-24009, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-1833 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Larva-24009 · UNKNOWN
ASEC reports continued activity by Larva-24009 (aka HeptaX per Cyble), a threat group active since at least 2023 that uses LNK-based spear phishing to deploy a PowerShell backdoor, the updated
Larva-24009, tracked independently by Cyble as "HeptaX" since a October 2024 report on unauthorized RDP-access tradecraft, has been active since at least 2023 running spear-phishing campaigns against a broad, non-specialized set of enterprise victims (healthcare, blockchain, finance, music/content creation) primarily in and around Korea but with global reach. On 2026-08-03 ASEC published a follow-up report documenting the group's continued and evolved operations.
The infection chain begins with a phishing email carrying a decoy LNK file disguised as a business document (hospital surveys, blockchain proposals, project proposals, resumes) — for example `NovaCX_Agency_Updated_2026047_091100_version_1_8.Docx.Lnk`. Execution of the LNK triggers an obfuscated PowerShell command that drops decoy files into `%TEMP%` while downloading further staged PowerShell scripts from the actor's C2 (`217.77.6.50`, endpoints under `/Res/`). These scripts install a custom PowerShell backdoor capable of screenshot capture and disabling Windows Defender, and deploy the updated Notifier malware (v2.1), which now reports infection status to the operators over the Telegram Bot API rather than only to the actor's own PHP-based C2 panel — a defense-evasion improvement that blends exfiltration traffic with legitimate, hard-to-block Telegram infrastructure.
For hands-on-keyboard access the actor installs QuasarRAT (an open-source, actively-maintained .NET RAT the group has used as its primary commodity RAT since at least 2024, having previously relied on njRAT) and an UltraVNC Server listening on the standard VNC ports 5800/5900, giving redundant remote-control channels. A batch script creates a hidden local backdoor account named "_BootUEFI_" (styled to blend in with UEFI/firmware-related system processes) for persistent, unauthorized access; the group's related HeptaX tradecraft (per Cyble, October 2024) additionally lowers Terminal Services authentication requirements to simplify unauthorized RDP logons and has been observed using the very similar account name "__BootUEFI__" with a static password, indicating a durable, reused TTP across campaign waves rather than a one-off artifact. Persistence for the PowerShell/Notifier components is established via Task Scheduler entries disguised as legitimate system tasks ("Intel(R) Ethernet3 Connection 1219-LM", "GoogleUpdateTaskMachineCoreUA2{...}", "GoogleUpdateTaskMachineCoreUA6{...}").
Credential and browsing-history harvesting is performed with a suite of legitimate NirSoft utilities (ChromePassView, WebBrowserBookmarksView, Network Password Recovery, LastActivityView) — a dual-use-tool pattern also documented in other financially- and espionage-motivated intrusions — plus a custom keylogger that writes captured keystrokes to `%ALLUSERSPROFILE%\Microsoft\OneDrive\log.Log` / `logv.Log`, a path chosen to masquerade as legitimate OneDrive telemetry. No CVE or software vulnerability is involved; the entire chain relies on social engineering (LNK execution) and living-off-the-land/dual-use tooling rather than exploitation.
Infrastructure pivoting against ASEC's prior October 2024 Larva-24009 report and Cyble's HeptaX report shows the group reusing infrastructure patterns (disposable `.shop`/`.site`/`.online` C2 domains, PHP-based C2 panels under `/Res/` or `/up/`) across at least two documented campaign waves (October 2024 and August 2026), with decoy-file embedded timestamps (e.g. `NovaCX_Interview_QA+Updated_20260420_162448_version_4_4.Docx.Lnk`) suggesting an intermediate wave in April 2026. A BeaconBeagle correlation check against the current C2 IP (`217.77.6.50`) and domains (`mainsec.site`, `aonexa.shop`) returned no existing indexed C2 configuration matches, consistent with newly-provisioned, campaign-specific infrastructure rather than long-lived shared C2.
Target sectors: health, blockchain, finance, music, content-creation, enterprise
Target regions: south korea, Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566.001, T1204.002, T1059.001, T1053.005, T1547.001, T1136.001, T1098, T1548.002, T1685