일본을 노리는 Larva-24005 그룹의 피싱 메일 공격 사례
2025-02-27 • Ahnlab • Cyber threat report on Phishing, Larva-24005 •
AhnLab reports that Larva-24005, identified as a Kimsuky sub-group, compromised poorly secured Windows RDP hosts in South Korea and used them as phishing infrastructure. The actor installed RDPWrap, a custom keylogger, XAMPP, PHPMailer, and Japanese IME support, with some infrastructure linked to BlueKeep CVE-2019-0708 exploitation. Targeting focused on Japan-based North Korea researchers, university professors, and NGOs, using Zoom-themed emails and Microsoft-style credential phishing pages tied to attacker C2 servers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-02-27 | 2025-02-27 |
Related Actors
Related Reports
Shares tags: Phishing, Larva-24005 • Shares 1 IOC • Same author: Ahnlab • Published within a week
Shares tag: Larva-24005 • Same author: Ahnlab
Shares tag: Larva-24005 • Same author: Ahnlab
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a month