Phishing Email Attacks by the Larva-24005 Group Targeting Japan

2025-02-27 Ahnlab

https://asec.ahnlab.com/en/86535/

Thumbnail for Phishing Email Attacks by the Larva-24005 Group Targeting Japan

AhnLab attributes a Japan-focused phishing operation to Larva-24005, a Kimsuky sub-group supported by North Korea. The actor compromised South Korean Windows systems over RDP, in some cases exploiting BlueKeep, then installed RDPWrap, a keylogger, XAMPP, and PHPMailer to operate phishing infrastructure and collect stolen data. The campaign targeted Japanese university professors and nonprofit personnel working on North Korea issues, using Zoom and web-portal themes, Japanese IME support, victim mailbox searches, and phishing pages impersonating iCloud, OneDrive, Outlook, Naver, and Google.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-27 2025-02-27
DOMAIN polypheou.jp 2025-02-27 2025-02-27

Related Actors

Related Reports

« Back