Larva-26005

Profile updated
2026-08-07 03:00:04

Context

Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found disguised as an integrated security program in an attack case reported by Hauri in 2026.

Reports & references

  • asec.ahnlab.com — 94847 (report)

External references