Larva-24009 Threat Actor’s 2026 Phishing Campaign Reveals Persistent Use of LNK Malware and Telegram-Based Exfiltration

Answer Brief

ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally.

Signal Timeline

A quick visual path for analysts before reading the full brief.

Timeline
  1. 1

    Larva-24009 threat actor first observed active

  2. 2

    ASEC previously disclosed attack cases by this threat actor

  3. 3

    ASEC published analysis of 2026 phishing email attack case

Executive Summary: ASEC’s analysis of a 2026 phishing email campaign by the Larva-24009 threat actor details how LNK files disguised as legitimate documents deploy PowerShell backdoors, QuasarRAT, UltraVNC, and NirSoft tools for credential theft, with persistence via scheduled tasks and exfiltration through the Telegram API, targeting users in Korea and globally.

Why It Matters

The Larva-24009 threat actor’s 2026 phishing campaign, as detailed by ASEC, reflects a mature and consistent operational pattern that has remained largely unchanged since at least 2023, underscoring the actor’s reliance on a proven, low-complexity attack chain that continues to evade detection through social engineering and living-off-the-land techniques. The campaign initiates with spearphishing emails containing LNK files masquerading as benign documents—such as resumes, project proposals, or hospital surveys—leveraging familiar file extensions to lower user suspicion. These LNK files, when executed, trigger an obfuscated PowerShell command that simultaneously drops a decoy document in the %TEMP% directory and downloads additional payloads from external C2 servers, a tactic designed to mimic legitimate software behavior while establishing covert access.

Once the initial PowerShell script executes, it establishes communication with C2 infrastructure to download components responsible for core malicious functions. These include scripts that disable Windows Defender to evade detection, capture screenshots for intelligence gathering, and log keystrokes to harvest credentials. Persistence is achieved not through registry modifications or service installations—which are more likely to trigger alerts—but via the creation of scheduled tasks with names deliberately mimicking legitimate system processes, such as those associated with Intel Ethernet adapters or Google Update mechanisms. This technique allows the malware to blend into routine system activity, reducing the likelihood of detection during manual or automated inspections that rely on process or task name anomalies.

Technical Signal

For remote system control, the threat actor deploys QuasarRAT, a well-known open-source remote access tool, and UltraVNC Server, which, when installed, opens TCP ports 5800 and 5900 to enable screen viewing and control via UltraVNC Viewer. The presence of a batch script on the download server that creates a backdoor account named '_BootUEFI_' further indicates the actor’s preparation for persistent administrative access, potentially through RDP exploitation, suggesting a layered approach to maintaining control even if one vector is blocked or detected.

Information gathering and credential theft are conducted using a combination of NirSoft utilities and custom PowerShell scripts. Tools like ChromePassView and WebBrowserBookmarksView extract stored credentials and browser data, while Network Password Recovery and LastActivityView retrieve network passwords and user activity logs, respectively. Custom keyloggers store input data in files named log.Log and logv.Log within the OneDrive directory under %ALLUSERSPROFILE%, a location likely selected to blend with legitimate user-generated cloud-synced data, thereby reducing the chance of discovery during routine file audits or antivirus scans that may overlook user profile directories.

Operational Impact

A notable evolution in the actor’s TTPs is the use of the Telegram API by the Notifier malware component to exfiltrate infection status. Unlike earlier versions that relied on direct HTTP POST requests to C2 servers—traffic that is more easily inspected and blocked by network security tools—the Telegram-based approach leverages an encrypted, widely trusted platform commonly allowed through corporate firewalls for legitimate communication. This shift reduces the visibility of malicious traffic, as Telegram traffic is often not subject to deep packet inspection or SSL decryption due to privacy concerns and performance overhead, providing the actor with a covert channel for low-volume, high-value data such as system identifiers, infection timestamps, or preliminary reconnaissance results.

The indicators of compromise (IOCs) tied to this campaign—including specific MD5 hashes of malware samples, C2 domains like aonexa[.]shop and final[.]mainsec2[.]site, and the IP address 217[.]77[.]6[.]50—remain consistent with those observed in prior years, indicating a stable, reusable toolkit rather than rapid tool development. This consistency suggests operational maturity, where the actor has refined a reliable attack chain and sees little need to overhaul it, focusing instead on refining delivery mechanisms (e.g., lure documents) and exfiltration methods (e.g., Telegram) to prolong campaign effectiveness.

What To Watch

For organizations, particularly those with operations or subsidiaries in South Korea where the actor has demonstrated regional targeting, the campaign underscores the importance of defending against phishing vectors that exploit document-based lures. User training should emphasize scrutiny of unexpected email attachments, especially LNK files, regardless of their apparent file type icon. Technical controls should include blocking LNK execution from email attachments, monitoring for anomalous scheduled tasks with legitimate-sounding names, detecting unauthorized installations of remote access tools like QuasarRAT or UltraVNC, and scrutinizing outbound connections to known malicious domains or unusual use of Telegram APIs from endpoints.

Defenders should also consider enabling logging of PowerShell script execution, particularly those that download from external sources or write to user profile directories like OneDrive, and monitoring for the creation of local accounts with names resembling system components (e.g., '_BootUEFI_'). Given the actor’s use of living-off-the-land binaries and trusted services, behavioral analytics—such as unusual process parent-child relationships, abnormal network destinations, or atypical file access patterns—are critical complements to signature-based defenses, which may fail to detect subtle variations in known malware families.

The regional focus of this reporting—originating from a South Korean threat intelligence source—provides valuable situational awareness for organizations operating in or connected to the Korean cyber threat landscape. While the actor’s activity is described as targeting users "both in Korea and globally," the observed cases and technical details are grounded in regional telemetry. English-language audiences should interpret this as first-hand insight into local TTPs that may inform detection rules, threat hunting hypotheses, or risk assessments for subsidiaries, partners, or supply chain nodes with Korean exposure, rather than as evidence of a widespread global incident lacking corroboration from other geographic sources.

For threat intelligence teams, the value of this report lies in its utility as a baseline for comparison. Monitoring for recurrence of similar LNK-based lure documents, PowerShell download chains, specific scheduled task names, NirSoft tool usage, or Telegram C2 behavior in internal logs or third-party feeds can help determine whether this activity represents an isolated incident or part of a persistent, regionally focused campaign. Retaining the original source links and IOCs enables accurate tracking and facilitates collaboration with regional CERTs or ISACs that may have additional context on actor infrastructure or victimology.

Event Type: security
Importance: high

Affected Companies

  • AhnLab
  • Cyble

Affected Sectors

  • cybersecurity
  • threat intelligence

Key Numbers

  • Active since: 2023
  • MD5 hash of malware sample: 10b40185106eb3760cb71c46117aa0bf
  • C2 domain used for Telegram exfiltration: aonexa[.]shop

Timeline

  1. Larva-24009 threat actor first observed active
  2. ASEC previously disclosed attack cases by this threat actor
  3. ASEC published analysis of 2026 phishing email attack case

Frequently Asked Questions

What is the primary infection vector used by the Larva-24009 threat actor?

The Larva-24009 threat actor uses phishing emails with LNK malware attachments disguised as legitimate documents such as hospital surveys, blockchain proposals, project documentation, and resumes to initiate infection.

How does the Larva-24009 threat actor maintain persistence on infected systems?

The threat actor maintains persistence by registering malicious tasks in Windows Task Scheduler with names like 'Intel(R) Ethernet3 Connection 1219-LM' and 'GoogleUpdateTaskMachineCoreUA2{F84AE75F-E9CE-4FC0-9BC8-998371F0931}', which execute PowerShell scripts for backdoor functionality.

What tools does the Larva-24009 threat actor use for information gathering and credential theft?

The threat actor uses NirSoft tools such as ChromePassView, WebBrowserBookmarksView, Network Password Recovery, and LastActivityView, along with custom PowerShell keyloggers that store logs in %ALLUSERSPROFILE%\Microsoft\OneDrive\log.Log and logv.Log.

How has the Larva-24009 threat actor’s command-and-control infrastructure evolved in 2026 compared to prior years?

In 2026, the Larva-24009 threat actor’s Notifier malware uses the Telegram API to exfiltrate infection status, a shift from earlier HTTP-based C2 communication, enabling stealthier data transmission via a trusted and encrypted platform less likely to be inspected by traditional network defenses.

What specific indicators of compromise (IOCs) are associated with the Larva-24009 threat actor’s 2026 campaign?

The campaign is associated with MD5 hashes including 10b40185106eb3760cb71c46117aa0bf, C2 domains such as aonexa[.]shop and final[.]mainsec2[.]site, and IP address 217[.]77[.]6[.]50, which defenders can use to detect and block related malicious activity.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *