Threat reportMalwareTL-2026-1908

Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)

criticalACTIVE

Larva-26005 APT Campaign (TL-2026-1908), also tracked as Larva-26005 campaign, is a critical-severity malware campaign, first published 2026-08-06. It is attributed to Lazarus Group (North Korea) with high confidence, affects Hancom Hangul Word Processor (HWP), references 1 CVE (CVE-2017-8291), maps to 19 MITRE ATT&CK techniques (T1027, T1036.005, T1053.005), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
2Lazarus Group
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-1908

Threat ID
TL-2026-1908
Also known as
Larva-26005 campaign, Xctdoor / CRAT operation, Operation ByteTiger
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Lazarus Group, Andariel
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
defense, manufacturing, government administration, academic, finance, energy, corporate
Target regions
south korea, Asia
Detection rules
9
Indicators of compromise
35

Malware and tooling in Larva-26005 APT Campaign

Malware and tooling: CRAT, Hansom, Tiger RAT, XcLoader, Xctdoor, ngrok - S0508

How Larva-26005 APT Campaign works

The North Korea-aligned Larva-26005 threat actor (Lazarus Group / Andariel subgroup) has run a long-lived multi-stage campaign against South Korean corporate and general users since April 2020, distributing the Xctdoor and CRAT backdoors plus the Hansom ransomware. As of mid-2026 the actor continues active LNK-based spear phishing, with infection chains progressing from a VBS launcher to a BAT downloader, PowerShell, and the XcLoader injector that loads Xctdoor into trusted system processes via DLL side-loading and Regsvr32.

Larva-26005 is AhnLab ASEC's designation for a threat cluster assessed to be linked to the Lazarus Group, and specifically the Andariel subgroup, a North Korean state-sponsored APT. Since April 2020 the actor has repeatedly targeted South Korean organizations and general users with a family of backdoors: CRAT (a modular remote access trojan), Xctdoor (a C++ and later Go-language backdoor), and the XcLoader process injector, along with the Hansom ransomware delivered as a CRAT plugin. Attribution is supported by code reuse (an identical HTTP wrapper library and overlapping RAT functionality with Lazarus implants), shared WordPress-based C2 infrastructure, overlapping C2 domains with Kaspersky's ThreatNeedle cluster and Google TAG's North Korea researcher-targeting campaign, and consistent use of Korean ERP supply-chain compromise that mirrors Andariel's 2017 HotCroissant/Rifdoor operation. AhnLab tracks the cluster as Larva-26005 and assesses a North Korean link with high confidence.

Infection vectors have evolved over the campaign. In 2020, malicious Hangul (HWP) documents exploiting CVE-2017-8291 delivered CRATv1, with a PowerShell + Regsvr32 activation chain. In 2021, Kaspersky documented Andariel using malicious Word documents and PDF-decoy files (via the Korean ezPDFReader) leading to an HTA -> second-stage loader -> backdoor chain, with a custom AES-128 ransomware (mshelp.exe) deployed against one South Korean victim. In 2024 the actor shifted to supply-chain and server compromise: an unmanaged Windows IIS web server was breached and loaded with a web shell, XcLoader, Xctdoor and the Ngrok tunneling tool; a groupware file-upload page was exploited to plant a malicious BeeBEEP open-source messenger installer for lateral movement; and the update server of a Korean ERP solution (K-System from YoungLimOne Softlab) was patched so ClientUpdater.exe executes the Go-variant Xctdoor via Regsvr32.exe, targeting the defense industry. Through 2026 the primary vector is LNK-based spear phishing (decoy names such as 'Comprehensive Status Report (Confidential)'), combined with a security-software-disguise chain that uses DLL side-loading (ShellRunAs -> credui.DLL or wkspbroker.exe -> RADCUI.DLL).

The 2026 infection chain (Chain A, security-software disguise) starts from a compressed file containing a legitimate EXE plus a malicious DLL. The DLL side-loads a dropper that decrypts a legitimate installer (Setup.Dat) for camouflage and drops a VBS launcher at %PUBLIC%\videos\s{random}.Vbs. The VBS launches a BAT downloader (%PUBLIC%\videos\{random}.Bat) which downloads encrypted Xctdoor, encrypted XcLoader, and a PowerShell script (2.Ps1) from hxxp://hesenorm[.]info/download/{xtps,lcpy,pxt2}. The VBS downloader p{random}.Vbs is registered in Task Scheduler for persistence. PowerShell performs XOR decryption (key: data XOR 0x11 XOR ((i*i) mod 0xFF)) and file moves, placing Xctdoor at %LOCALAPPDATA%\Packages\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\Settings\roaming.Dat and XcLoader at ...\Settings\settings.Lock. XcLoader is executed via 'regsvr32.exe /s ...settings.Lock', reads and decrypts roaming.Dat, injects Xctdoor into a target process (default explorer.exe), and creates a startup-folder shortcut for persistence. The AppX-package installation paths are abused to masquerade as legitimate Microsoft components.

Xctdoor is a full-featured backdoor exposing 30+ commands (0x10001-0x10029): interactive shell and hidden command execution via CreateProcess, drive and file enumeration, three-phase file download and two-phase upload, recursive deletion, system-info collection, process listing/kill, keylogging start/stop, screenshot capture, configuration changes (interval, port, keylogging/screenshot settings), and shared-memory management. It performs user-absence detection (screensaver active, monitor off, or session locked) and reports absence state changes to the C2. It is a self-modifying PE: it re-encrypts its own obfuscation signature/key values back into roaming.Dat to defeat static signatures. Both Xctdoor and XcLoader use a start/end-signature pattern-based obfuscation that is deobfuscated at function entry and re-obfuscated at exit.

CRAT (first identified April 2020) is a modular RAT attributed to Lazarus: it communicates over HTTP with URL-encoded form data using a random-DWORD XOR + Base64 exfiltration algorithm, self-injects into legitimate processes (sihost.exe, taskhostw.exe, ApplicationFrameHost.exe, svchost.exe, explorer.exe), uses a named pipe (\\.\Pipe\ChromeUpdatePipe) for inter-module communication, and downloads plugins: a screen-capture plugin (TIFF output), a clipboard monitor, a keylogger, and the Hansom ransomware. Hansom is unusual: rather than encrypting files directly, it archives each target into an individually password-protected RAR archive, encrypts the RAR password with an embedded RSA public key, appends the encrypted password blob, and drops a HANSOM_README.txt ransom note. It terminates database/office/AV processes, suppresses Windows Defender notifications, disables Task Manager, deletes Volume Shadow Copies (wmic shadowcopy delete), and changes the desktop wallpaper. Talos notes the ransom BTC addresses held 0 BTC, suggesting Hansom may function as endpoint-destruction pseudo-ransomware.

The campaign demonstrates sustained focus on South Korean targets across defense, manufacturing, government/academic, ERP, groupware, and general-user segments, with a combination of espionage objectives and financially motivated ransomware deployment consistent with Andariel's history.

MITRE ATT&CK techniques used in TL-2026-1908

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Dynamic-link Library Injection

Persistence

T1053.005 Scheduled Task; T1505.002 Transport Agent; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1056.001 Keylogging

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols

Discovery

T1082 System Information Discovery

Collection

T1113 Screen Capture

Initial Access

T1190 Exploit Public-Facing Application; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment

stealth

T1218.010 Regsvr32; T1574.001 DLL

Affected products and versions in Larva-26005 APT Campaign

  • Hancom — Hangul Word Processor (HWP)
    Vulnerable versions: 2014 and earlier versions affected by CVE-2017-8291
    Fixed in: 2014 with the CVE-2017-8291 patch
  • YoungLimOne Softlab — K-System ERP solution
    Vulnerable versions: Update client (ClientUpdater.exe) distribution channel
    Fixed in: Verify updated module hashes; compromise was on the update server
  • Microsoft — Windows (IIS, groupware, endpoint)
    Vulnerable versions: IIS 8.5 web servers with poor configurations; Windows endpoints where Regsvr32/PowerShell abuse is unmonitored
    Fixed in: Hardened configurations and EDR coverage

Remediation for Larva-26005 APT Campaign

Patches

  • Apply patches for CVE-2017-8291 (Hangul Word Processor remote code execution)
  • Harden and update Korean ERP solution (K-System / ClientUpdater.exe) and groupware applications
  • Update Windows IIS and maintain patched web servers to close the public-facing application vectors used in 2024

Immediate actions

  • Block the identified C2 and download domains (hesenorm.info, casinolegit.fun, koramate.fun, ntsgo-corp.com, ntsgo.name, beebeep.info) and the historical Andariel C2 IPs at the perimeter
  • Hunt for LNK files with decoy names such as 'Comprehensive Status Report (Confidential)' and quarantine them
  • Search for the AppX-path indicators of compromise (roaming.Dat / settings.Lock under Microsoft.MicrosoftOffice365Hub and MicrosoftEdge.Current package folders) on endpoints
  • Disable or tightly restrict Regsvr32.exe and mshta.exe execution where business need does not require them

Workarounds

  • Restrict PowerShell and VBS script execution from writable user directories such as %PUBLIC%\videos
  • Block outbound HTTP POSTs to uncategorized domains from endpoints where no business justification exists
  • Disable task scheduler creation of tasks pointing at VBS scripts in public folders

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading, process injection (explorer.exe injection), and self-modifying PE behavior
  • Monitor for new RAR-archive creation with WinRAR + password flags and shadow-copy deletion as Hansom indicators
  • Apply supply-chain controls: verify hash integrity of Korean ERP (K-System) update modules and groupware upload pages
  • Segment IIS/ERP/groupware servers and audit for web shells and unauthorized Ngrok tunnels

CVEs associated with Larva-26005 APT Campaign

CVE-2017-8291

Weaknesses (CWE) in Larva-26005 APT Campaign

CWE-94

Timeline of Larva-26005 APT Campaign

  • CVE-2017-8291 (Hangul Word Processor RCE) disclosed; later exploited by the actor to deliver CRAT via malicious HWP documents in 2020.
  • Andariel group compromises a Korean ERP solution update channel to install the HotCroissant (Rifdoor) backdoor via ClientUpdater.exe - the same supply-chain pattern later reused for Xctdoor.
  • CRAT (v1) backdoor first identified, delivered via malicious HWP documents exploiting CVE-2017-8291 with a PowerShell + Regsvr32 activation chain.
  • CRAT distributed via South Korean community sites; the Hansom ransomware plugin is spotted in the wild; early Xctdoor and CRAT jointly deployed in Korean attacks.
  • Cisco Talos publishes 'CRAT wants to plunder your endpoints', detailing the modular CRAT RAT, its plugins (keylogger, screen capture, clipboard monitor, Hansom ransomware), and Lazarus attribution.
  • Malicious Word documents (e.g. 'Application Form' 참가신청서양식.doc) and PDF-decoy files distribute the Andariel second/third-stage backdoor; Kaspersky later attributes the campaign to Andariel.
  • Korea CERT (KrCERT) reports the 'ByteTiger' operation; malware families later established as TigerDownloader and TigerRAT by ThreatRay.
  • Windows IIS 8.5 web servers compromised (poor configuration/vulnerability); web shell, XcLoader, Xctdoor, and Ngrok tunnel installed - targets Korean manufacturing sector.
  • AhnLab confirms the Korean ERP solution K-System update server was compromised; ClientUpdater.exe modified to execute the Go-variant Xctdoor via Regsvr32.exe, targeting the Korean defense industry.
  • AhnLab ASEC publishes detailed Xctdoor (Go variant) and XcLoader analysis, noting first identification of the Go-variant XcLoader in this attack.
  • Hauri discloses Veraport-disguised Xctdoor attacks, highlighting security-software impersonation as an ongoing vector.
  • LNK-based spear phishing observed using decoy filenames such as 'Comprehensive Status Report (Confidential)' to target corporate users.
  • AhnLab ASEC publishes the comprehensive Larva-26005 analysis connecting Xctdoor and past CRAT attack cases, documenting the 2020-2026 campaign and its full infection chains.

Sources cited for Larva-26005 APT Campaign

Detection coverage for TL-2026-1908

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1908 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1908

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats