Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026) — Threadlinqs Intelligence
As of 2026-08-06, Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026) is a critical-severity malware threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1908 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: Lazarus Group · North Korea · ESPIONAGE
The North Korea-aligned Larva-26005 threat actor (Lazarus Group / Andariel subgroup) has run a long-lived multi-stage campaign against South Korean corporate and general users since April 2020,
Larva-26005 is AhnLab ASEC's designation for a threat cluster assessed to be linked to the Lazarus Group, and specifically the Andariel subgroup, a North Korean state-sponsored APT. Since April 2020 the actor has repeatedly targeted South Korean organizations and general users with a family of backdoors: CRAT (a modular remote access trojan), Xctdoor (a C++ and later Go-language backdoor), and the XcLoader process injector, along with the Hansom ransomware delivered as a CRAT plugin. Attribution is supported by code reuse (an identical HTTP wrapper library and overlapping RAT functionality with Lazarus implants), shared WordPress-based C2 infrastructure, overlapping C2 domains with Kaspersky's ThreatNeedle cluster and Google TAG's North Korea researcher-targeting campaign, and consistent use of Korean ERP supply-chain compromise that mirrors Andariel's 2017 HotCroissant/Rifdoor operation. AhnLab tracks the cluster as Larva-26005 and assesses a North Korean link with high confidence.
Infection vectors have evolved over the campaign. In 2020, malicious Hangul (HWP) documents exploiting CVE-2017-8291 delivered CRATv1, with a PowerShell + Regsvr32 activation chain. In 2021, Kaspersky documented Andariel using malicious Word documents and PDF-decoy files (via the Korean ezPDFReader) leading to an HTA -> second-stage loader -> backdoor chain, with a custom AES-128 ransomware (mshelp.exe) deployed against one South Korean victim. In 2024 the actor shifted to supply-chain and server compromise: an unmanaged Windows IIS web server was breached and loaded with a web shell, XcLoader, Xctdoor and the Ngrok tunneling tool; a groupware file-upload page was exploited to plant a malicious BeeBEEP open-source messenger installer for lateral movement; and the update server of a Korean ERP solution (K-System from YoungLimOne Softlab) was patched so ClientUpdater.exe executes the Go-variant Xctdoor via Regsvr32.exe, targeting the defense industry. Through 2026 the primary vector is LNK-based spear phishing (decoy names such as 'Comprehensive Status Report (Confidential)'), combined with a security-software-disguise chain that uses DLL side-loading (ShellRunAs -> credui.DLL or wkspbroker.exe -> RADCUI.DLL).
The 2026 infection chain (Chain A, security-software disguise) starts from a compressed file containing a legitimate EXE plus a malicious DLL. The DLL side-loads a dropper that decrypts a legitimate installer (Setup.Dat) for camouflage and drops a VBS launcher at %PUBLIC%\videos\s{random}.Vbs. The VBS launches a BAT downloader (%PUBLIC%\videos\{random}.Bat) which downloads encrypted Xctdoor, encrypted XcLoader, and a PowerShell script (2.Ps1) from hxxp://hesenorm[.]info/download/{xtps,lcpy,pxt2}. The VBS downloader p{random}.Vbs is registered in Task Scheduler for persistence. PowerShell performs XOR decryption (key: data XOR 0x11 XOR ((i*i) mod 0xFF)) and file moves, placing Xctdoor at %LOCALAPPDATA%\Packages\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\Settings\roaming.Dat and XcLoader at ...\Settings\settings.Lock. XcLoader is executed via 'regsvr32.exe /s ...settings.Lock', reads and decrypts roaming.Dat, injects Xctdoor into a target process (default explorer.exe), and creates a startup-folder shortcut for persistence. The AppX-package installation paths are abused to masquerade as legitimate Microsoft components.
Xctdoor is a full-featured backdoor exposing 30+ commands (0x10001-0x10029): interactive shell and hidden command execution via CreateProcess, drive and file enumeration, three-phase file download and two-phase upload, recursive deletion, system-info collection, process listing/kill, keylogging start/stop, screenshot capture, configuration changes (interval, port, keylogging/screenshot settings), and shared-memory management. It performs user-absence detection (screensaver active, monitor off, or session locked) and reports absence state changes to the C2. It is a self-modifying PE: it re-encrypts its own obfuscation signatur
Target sectors: defense, manufacturing, government administration, academic, finance, energy, corporate
Target regions: south korea, Asia
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2017-8291, T1566.001, T1190, T1195.002, T1204.002, T1059.001, T1059.003, T1059.005, T1218.010, T1053.005, T1547.001