Threat reportMalwareTL-2026-1908
Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)
Larva-26005 APT Campaign (TL-2026-1908), also tracked as Larva-26005 campaign, is a critical-severity malware campaign, first published 2026-08-06. It is attributed to Lazarus Group (North Korea) with high confidence, affects Hancom Hangul Word Processor (HWP), references 1 CVE (CVE-2017-8291), maps to 19 MITRE ATT&CK techniques (T1027, T1036.005, T1053.005), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 2Lazarus Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-1908
- Threat ID
- TL-2026-1908
- Also known as
- Larva-26005 campaign, Xctdoor / CRAT operation, Operation ByteTiger
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Lazarus Group, Andariel
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- defense, manufacturing, government administration, academic, finance, energy, corporate
- Target regions
- south korea, Asia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in Larva-26005 APT Campaign
Malware and tooling: CRAT, Hansom, Tiger RAT, XcLoader, Xctdoor, ngrok - S0508
How Larva-26005 APT Campaign works
The North Korea-aligned Larva-26005 threat actor (Lazarus Group / Andariel subgroup) has run a long-lived multi-stage campaign against South Korean corporate and general users since April 2020, distributing the Xctdoor and CRAT backdoors plus the Hansom ransomware. As of mid-2026 the actor continues active LNK-based spear phishing, with infection chains progressing from a VBS launcher to a BAT downloader, PowerShell, and the XcLoader injector that loads Xctdoor into trusted system processes via DLL side-loading and Regsvr32.
Larva-26005 is AhnLab ASEC's designation for a threat cluster assessed to be linked to the Lazarus Group, and specifically the Andariel subgroup, a North Korean state-sponsored APT. Since April 2020 the actor has repeatedly targeted South Korean organizations and general users with a family of backdoors: CRAT (a modular remote access trojan), Xctdoor (a C++ and later Go-language backdoor), and the XcLoader process injector, along with the Hansom ransomware delivered as a CRAT plugin. Attribution is supported by code reuse (an identical HTTP wrapper library and overlapping RAT functionality with Lazarus implants), shared WordPress-based C2 infrastructure, overlapping C2 domains with Kaspersky's ThreatNeedle cluster and Google TAG's North Korea researcher-targeting campaign, and consistent use of Korean ERP supply-chain compromise that mirrors Andariel's 2017 HotCroissant/Rifdoor operation. AhnLab tracks the cluster as Larva-26005 and assesses a North Korean link with high confidence.
Infection vectors have evolved over the campaign. In 2020, malicious Hangul (HWP) documents exploiting CVE-2017-8291 delivered CRATv1, with a PowerShell + Regsvr32 activation chain. In 2021, Kaspersky documented Andariel using malicious Word documents and PDF-decoy files (via the Korean ezPDFReader) leading to an HTA -> second-stage loader -> backdoor chain, with a custom AES-128 ransomware (mshelp.exe) deployed against one South Korean victim. In 2024 the actor shifted to supply-chain and server compromise: an unmanaged Windows IIS web server was breached and loaded with a web shell, XcLoader, Xctdoor and the Ngrok tunneling tool; a groupware file-upload page was exploited to plant a malicious BeeBEEP open-source messenger installer for lateral movement; and the update server of a Korean ERP solution (K-System from YoungLimOne Softlab) was patched so ClientUpdater.exe executes the Go-variant Xctdoor via Regsvr32.exe, targeting the defense industry. Through 2026 the primary vector is LNK-based spear phishing (decoy names such as 'Comprehensive Status Report (Confidential)'), combined with a security-software-disguise chain that uses DLL side-loading (ShellRunAs -> credui.DLL or wkspbroker.exe -> RADCUI.DLL).
The 2026 infection chain (Chain A, security-software disguise) starts from a compressed file containing a legitimate EXE plus a malicious DLL. The DLL side-loads a dropper that decrypts a legitimate installer (Setup.Dat) for camouflage and drops a VBS launcher at %PUBLIC%\videos\s{random}.Vbs. The VBS launches a BAT downloader (%PUBLIC%\videos\{random}.Bat) which downloads encrypted Xctdoor, encrypted XcLoader, and a PowerShell script (2.Ps1) from hxxp://hesenorm[.]info/download/{xtps,lcpy,pxt2}. The VBS downloader p{random}.Vbs is registered in Task Scheduler for persistence. PowerShell performs XOR decryption (key: data XOR 0x11 XOR ((i*i) mod 0xFF)) and file moves, placing Xctdoor at %LOCALAPPDATA%\Packages\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\Settings\roaming.Dat and XcLoader at ...\Settings\settings.Lock. XcLoader is executed via 'regsvr32.exe /s ...settings.Lock', reads and decrypts roaming.Dat, injects Xctdoor into a target process (default explorer.exe), and creates a startup-folder shortcut for persistence. The AppX-package installation paths are abused to masquerade as legitimate Microsoft components.
Xctdoor is a full-featured backdoor exposing 30+ commands (0x10001-0x10029): interactive shell and hidden command execution via CreateProcess, drive and file enumeration, three-phase file download and two-phase upload, recursive deletion, system-info collection, process listing/kill, keylogging start/stop, screenshot capture, configuration changes (interval, port, keylogging/screenshot settings), and shared-memory management. It performs user-absence detection (screensaver active, monitor off, or session locked) and reports absence state changes to the C2. It is a self-modifying PE: it re-encrypts its own obfuscation signature/key values back into roaming.Dat to defeat static signatures. Both Xctdoor and XcLoader use a start/end-signature pattern-based obfuscation that is deobfuscated at function entry and re-obfuscated at exit.
CRAT (first identified April 2020) is a modular RAT attributed to Lazarus: it communicates over HTTP with URL-encoded form data using a random-DWORD XOR + Base64 exfiltration algorithm, self-injects into legitimate processes (sihost.exe, taskhostw.exe, ApplicationFrameHost.exe, svchost.exe, explorer.exe), uses a named pipe (\\.\Pipe\ChromeUpdatePipe) for inter-module communication, and downloads plugins: a screen-capture plugin (TIFF output), a clipboard monitor, a keylogger, and the Hansom ransomware. Hansom is unusual: rather than encrypting files directly, it archives each target into an individually password-protected RAR archive, encrypts the RAR password with an embedded RSA public key, appends the encrypted password blob, and drops a HANSOM_README.txt ransom note. It terminates database/office/AV processes, suppresses Windows Defender notifications, disables Task Manager, deletes Volume Shadow Copies (wmic shadowcopy delete), and changes the desktop wallpaper. Talos notes the ransom BTC addresses held 0 BTC, suggesting Hansom may function as endpoint-destruction pseudo-ransomware.
The campaign demonstrates sustained focus on South Korean targets across defense, manufacturing, government/academic, ERP, groupware, and general-user segments, with a combination of espionage objectives and financially motivated ransomware deployment consistent with Andariel's history.
MITRE ATT&CK techniques used in TL-2026-1908
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Dynamic-link Library Injection
Persistence
T1053.005 Scheduled Task; T1505.002 Transport Agent; T1547.001 Registry Run Keys / Startup Folder
Credential Access
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.002 Malicious File
Command and Control
Discovery
T1082 System Information Discovery
Collection
Initial Access
T1190 Exploit Public-Facing Application; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment
stealth
Affected products and versions in Larva-26005 APT Campaign
- Hancom — Hangul Word Processor (HWP)
Vulnerable versions: 2014 and earlier versions affected by CVE-2017-8291
Fixed in: 2014 with the CVE-2017-8291 patch - YoungLimOne Softlab — K-System ERP solution
Vulnerable versions: Update client (ClientUpdater.exe) distribution channel
Fixed in: Verify updated module hashes; compromise was on the update server - Microsoft — Windows (IIS, groupware, endpoint)
Vulnerable versions: IIS 8.5 web servers with poor configurations; Windows endpoints where Regsvr32/PowerShell abuse is unmonitored
Fixed in: Hardened configurations and EDR coverage
Remediation for Larva-26005 APT Campaign
Patches
- Apply patches for CVE-2017-8291 (Hangul Word Processor remote code execution)
- Harden and update Korean ERP solution (K-System / ClientUpdater.exe) and groupware applications
- Update Windows IIS and maintain patched web servers to close the public-facing application vectors used in 2024
Immediate actions
- Block the identified C2 and download domains (hesenorm.info, casinolegit.fun, koramate.fun, ntsgo-corp.com, ntsgo.name, beebeep.info) and the historical Andariel C2 IPs at the perimeter
- Hunt for LNK files with decoy names such as 'Comprehensive Status Report (Confidential)' and quarantine them
- Search for the AppX-path indicators of compromise (roaming.Dat / settings.Lock under Microsoft.MicrosoftOffice365Hub and MicrosoftEdge.Current package folders) on endpoints
- Disable or tightly restrict Regsvr32.exe and mshta.exe execution where business need does not require them
Workarounds
- Restrict PowerShell and VBS script execution from writable user directories such as %PUBLIC%\videos
- Block outbound HTTP POSTs to uncategorized domains from endpoints where no business justification exists
- Disable task scheduler creation of tasks pointing at VBS scripts in public folders
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading, process injection (explorer.exe injection), and self-modifying PE behavior
- Monitor for new RAR-archive creation with WinRAR + password flags and shadow-copy deletion as Hansom indicators
- Apply supply-chain controls: verify hash integrity of Korean ERP (K-System) update modules and groupware upload pages
- Segment IIS/ERP/groupware servers and audit for web shells and unauthorized Ngrok tunnels
CVEs associated with Larva-26005 APT Campaign
Weaknesses (CWE) in Larva-26005 APT Campaign
Timeline of Larva-26005 APT Campaign
- CVE-2017-8291 (Hangul Word Processor RCE) disclosed; later exploited by the actor to deliver CRAT via malicious HWP documents in 2020.
- Andariel group compromises a Korean ERP solution update channel to install the HotCroissant (Rifdoor) backdoor via ClientUpdater.exe - the same supply-chain pattern later reused for Xctdoor.
- CRAT (v1) backdoor first identified, delivered via malicious HWP documents exploiting CVE-2017-8291 with a PowerShell + Regsvr32 activation chain.
- CRAT distributed via South Korean community sites; the Hansom ransomware plugin is spotted in the wild; early Xctdoor and CRAT jointly deployed in Korean attacks.
- Cisco Talos publishes 'CRAT wants to plunder your endpoints', detailing the modular CRAT RAT, its plugins (keylogger, screen capture, clipboard monitor, Hansom ransomware), and Lazarus attribution.
- Malicious Word documents (e.g. 'Application Form' 참가신청서양식.doc) and PDF-decoy files distribute the Andariel second/third-stage backdoor; Kaspersky later attributes the campaign to Andariel.
- Korea CERT (KrCERT) reports the 'ByteTiger' operation; malware families later established as TigerDownloader and TigerRAT by ThreatRay.
- Windows IIS 8.5 web servers compromised (poor configuration/vulnerability); web shell, XcLoader, Xctdoor, and Ngrok tunnel installed - targets Korean manufacturing sector.
- AhnLab confirms the Korean ERP solution K-System update server was compromised; ClientUpdater.exe modified to execute the Go-variant Xctdoor via Regsvr32.exe, targeting the Korean defense industry.
- AhnLab ASEC publishes detailed Xctdoor (Go variant) and XcLoader analysis, noting first identification of the Go-variant XcLoader in this attack.
- Hauri discloses Veraport-disguised Xctdoor attacks, highlighting security-software impersonation as an ongoing vector.
- LNK-based spear phishing observed using decoy filenames such as 'Comprehensive Status Report (Confidential)' to target corporate users.
- AhnLab ASEC publishes the comprehensive Larva-26005 analysis connecting Xctdoor and past CRAT attack cases, documenting the 2020-2026 campaign and its full infection chains.
Sources cited for Larva-26005 APT Campaign
- AhnLab ASEC: Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
- AhnLab ASEC: Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)
- AhnLab ASEC: May 2024 APT Report (K-System ERP update server compromise)
- Cisco Talos: CRAT wants to plunder your endpoints (CRAT, Hansom ransomware, Lazarus)
- Kaspersky Securelist: Andariel evolves to target South Korea with ransomware
- Kaspersky ICS CERT: Lazarus targets defense industry with ThreatNeedle
- The Hacker News: South Korean ERP Vendor's Server Hacked to Distribute Xctdoor Malware
- ThreatRay: Establishing the TigerRAT and TigerDownloader malware families
- NVD: CVE-2017-8291 (Hangul Word Processor RCE)
Detection coverage for TL-2026-1908
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1908 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1908
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.