# Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)

> The North Korea-aligned Larva-26005 threat actor (Lazarus Group / Andariel subgroup) has run a long-lived multi-stage campaign against South Korean corporate and general users since April 2020, distributing the Xctdoor and CRAT backdoors plus the Hansom ransomware. As of mid-2026 the actor continues active LNK-based spear phishing, with infection chains progressing from a VBS launcher to a BAT downloader, PowerShell, and the XcLoader injector that loads Xctdoor into trusted system processes via DLL side-loading and Regsvr32.

- **Published:** 2026-08-06T00:00:00Z
- **Last reviewed:** 2026-08-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1908
- **ID:** TL-2026-1908
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Lazarus Group (North Korea)
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2017-8291

## Description

Larva-26005 is AhnLab ASEC's designation for a threat cluster assessed to be linked to the Lazarus Group, and specifically the Andariel subgroup, a North Korean state-sponsored APT. Since April 2020 the actor has repeatedly targeted South Korean organizations and general users with a family of backdoors: CRAT (a modular remote access trojan), Xctdoor (a C++ and later Go-language backdoor), and the XcLoader process injector, along with the Hansom ransomware delivered as a CRAT plugin. Attribution is supported by code reuse (an identical HTTP wrapper library and overlapping RAT functionality with Lazarus implants), shared WordPress-based C2 infrastructure, overlapping C2 domains with Kaspersky's ThreatNeedle cluster and Google TAG's North Korea researcher-targeting campaign, and consistent use of Korean ERP supply-chain compromise that mirrors Andariel's 2017 HotCroissant/Rifdoor operation. AhnLab tracks the cluster as Larva-26005 and assesses a North Korean link with high confidence.

Infection vectors have evolved over the campaign. In 2020, malicious Hangul (HWP) documents exploiting CVE-2017-8291 delivered CRATv1, with a PowerShell + Regsvr32 activation chain. In 2021, Kaspersky documented Andariel using malicious Word documents and PDF-decoy files (via the Korean ezPDFReader) leading to an HTA -> second-stage loader -> backdoor chain, with a custom AES-128 ransomware (mshelp.exe) deployed against one South Korean victim. In 2024 the actor shifted to supply-chain and server compromise: an unmanaged Windows IIS web server was breached and loaded with a web shell, XcLoader, Xctdoor and the Ngrok tunneling tool; a groupware file-upload page was exploited to plant a malicious BeeBEEP open-source messenger installer for lateral movement; and the update server of a Korean ERP solution (K-System from YoungLimOne Softlab) was patched so ClientUpdater.exe executes the Go-variant Xctdoor via Regsvr32.exe, targeting the defense industry. Through 2026 the primary vector is LNK-based spear phishing (decoy names such as 'Comprehensive Status Report (Confidential)'), combined with a security-software-disguise chain that uses DLL side-loading (ShellRunAs -> credui.DLL or wkspbroker.exe -> RADCUI.DLL).

The 2026 infection chain (Chain A, security-software disguise) starts from a compressed file containing a legitimate EXE plus a malicious DLL. The DLL side-loads a dropper that decrypts a legitimate installer (Setup.Dat) for camouflage and drops a VBS launcher at %PUBLIC%\videos\s{random}.Vbs. The VBS launches a BAT downloader (%PUBLIC%\videos\{random}.Bat) which downloads encrypted Xctdoor, encrypted XcLoader, and a PowerShell script (2.Ps1) from hxxp://hesenorm[.]info/download/{xtps,lcpy,pxt2}. The VBS downloader p{random}.Vbs is registered in Task Scheduler for persistence. PowerShell performs XOR decryption (key: data XOR 0x11 XOR ((i*i) mod 0xFF)) and file moves, placing Xctdoor at %LOCALAPPDATA%\Packages\Microsoft.MicrosoftOffice365Hub_8wekyb3d8bbwe\Settings\roaming.Dat and XcLoader at ...\Settings\settings.Lock. XcLoader is executed via 'regsvr32.exe /s ...settings.Lock', reads and decrypts roaming.Dat, injects Xctdoor into a target process (default explorer.exe), and creates a startup-folder shortcut for persistence. The AppX-package installation paths are abused to masquerade as legitimate Microsoft components.

Xctdoor is a full-featured backdoor exposing 30+ commands (0x10001-0x10029): interactive shell and hidden command execution via CreateProcess, drive and file enumeration, three-phase file download and two-phase upload, recursive deletion, system-info collection, process listing/kill, keylogging start/stop, screenshot capture, configuration changes (interval, port, keylogging/screenshot settings), and shared-memory management. It performs user-absence detection (screensaver active, monitor off, or session locked) and reports absence state changes to the C2. It is a self-modifying PE: it re-encrypts its own obfuscation signature/key values back into roaming.Dat to defeat static signatures. Both Xctdoor and XcLoader use a start/end-signature pattern-based obfuscation that is deobfuscated at function entry and re-obfuscated at exit.

CRAT (first identified April 2020) is a modular RAT attributed to Lazarus: it communicates over HTTP with URL-encoded form data using a random-DWORD XOR + Base64 exfiltration algorithm, self-injects into legitimate processes (sihost.exe, taskhostw.exe, ApplicationFrameHost.exe, svchost.exe, explorer.exe), uses a named pipe (\\.\Pipe\ChromeUpdatePipe) for inter-module communication, and downloads plugins: a screen-capture plugin (TIFF output), a clipboard monitor, a keylogger, and the Hansom ransomware. Hansom is unusual: rather than encrypting files directly, it archives each target into an individually password-protected RAR archive, encrypts the RAR password with an embedded RSA public key, appends the encrypted password blob, and drops a HANSOM_README.txt ransom note. It terminates database/office/AV processes, suppresses Windows Defender notifications, disables Task Manager, deletes Volume Shadow Copies (wmic shadowcopy delete), and changes the desktop wallpaper. Talos notes the ransom BTC addresses held 0 BTC, suggesting Hansom may function as endpoint-destruction pseudo-ransomware.

The campaign demonstrates sustained focus on South Korean targets across defense, manufacturing, government/academic, ERP, groupware, and general-user segments, with a combination of espionage objectives and financially motivated ransomware deployment consistent with Andariel's history.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1190 Exploit Public-Facing Application
- T1195.002 Compromise Software Supply Chain
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1218.010 Regsvr32
- T1053.005 Scheduled Task
- T1547.001 Registry Run Keys / Startup Folder
- T1505.002 Transport Agent
- T1027 Obfuscated Files or Information
- T1055.001 Dynamic-link Library Injection
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1056.001 Keylogging
- T1082 System Information Discovery
- T1113 Screen Capture
- T1071.001 Web Protocols

## Sources

- [AhnLab ASEC: Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)](https://asec.ahnlab.com/en/94847/)
- [AhnLab ASEC: Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)](https://asec.ahnlab.com/en/74835/)
- [AhnLab ASEC: May 2024 APT Report (K-System ERP update server compromise)](https://asec.ahnlab.com/en/78873/)
- [Cisco Talos: CRAT wants to plunder your endpoints (CRAT, Hansom ransomware, Lazarus)](https://blog.talosintelligence.com/2020/11/crat-and-plugins.html)
- [Kaspersky Securelist: Andariel evolves to target South Korea with ransomware](https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/)
- [Kaspersky ICS CERT: Lazarus targets defense industry with ThreatNeedle](https://ics-cert.kaspersky.com/publications/reports/2021/02/25/lazarus-targets-defense-industry-with-threatneedle/)
- [The Hacker News: South Korean ERP Vendor's Server Hacked to Distribute Xctdoor Malware](https://thehackernews.com/2024/07/south-korean-erp-vendors-server-hacked.html)
- [ThreatRay: Establishing the TigerRAT and TigerDownloader malware families](https://www.threatray.com/blog/establishing-the-tigerrat-and-tigerdownloader-malware-families)
- [NVD: CVE-2017-8291 (Hangul Word Processor RCE)](https://nvd.nist.gov/vuln/detail/CVE-2017-8291)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1908
