Phishing Email Attacks by the Larva-24005 Group Targeting Japan
2025-02-27 • Ahnlab •
AhnLab attributes a Japan-focused phishing operation to Larva-24005, a Kimsuky sub-group supported by North Korea. The actor compromised South Korean Windows systems over RDP, in some cases exploiting BlueKeep, then installed RDPWrap, a keylogger, XAMPP, and PHPMailer to operate phishing infrastructure and collect stolen data. The campaign targeted Japanese university professors and nonprofit personnel working on North Korea issues, using Zoom and web-portal themes, Japanese IME support, victim mailbox searches, and phishing pages impersonating iCloud, OneDrive, Outlook, Naver, and Google.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-02-27 | 2025-02-27 | |
| DOMAIN | polypheou.jp | 2025-02-27 | 2025-02-27 |
Related Actors
Related Reports
Shares tags: Phishing, Larva-24005 • Shares 1 IOC • Same author: Ahnlab • Published within a week
Shares tag: Larva-24005 • Same author: Ahnlab
Shares tag: Larva-24005 • Same author: Ahnlab
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a week
Shares tag: Phishing • Published within a month