일본을 노리는 Larva-24005 그룹의 피싱 메일 공격 사례

2025-02-27 Ahnlab Cyber threat report on Phishing, Larva-24005

https://asec.ahnlab.com/ko/86522/

Thumbnail for 일본을 노리는 Larva-24005 그룹의 피싱 메일 공격 사례

AhnLab reports that Larva-24005, identified as a Kimsuky sub-group, compromised poorly secured Windows RDP hosts in South Korea and used them as phishing infrastructure. The actor installed RDPWrap, a custom keylogger, XAMPP, PHPMailer, and Japanese IME support, with some infrastructure linked to BlueKeep CVE-2019-0708 exploitation. Targeting focused on Japan-based North Korea researchers, university professors, and NGOs, using Zoom-themed emails and Microsoft-style credential phishing pages tied to attacker C2 servers.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-27 2025-02-27

Related Actors

Related Reports

« Back