Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

1. Overview AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security

Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)

AhnLab SEcurity intelligence Center (ASEC) recently discovered a case where an unidentified threat actor exploited a Korean ERP solution to carry out an attack. After infiltrating the system, the threat actor is believed to have attacked the update server of a specific Korean ERP solution to take control of systems