216.73.216.233

APT Group Profiles - Larva-24005

· Published 22/04/2025 16:40 · Modified 22/04/2025 22:49

Export JSON

Essential information

Published
22/04/2025 16:40
Modified
22/04/2025 22:49
Tags
2025-04-22 CVE-2017-11882 CVE-2019-0708 apt bluekeep japan keylogger kimalogger kimsuky myspy phishing randomquery rdp exploitation south korea
Related entities
1 intrusion sets (apt), 3 malware, 16 others

Description

A new operation named Larva-24005, linked to the group, has been discovered by ASEC. The threat actors exploited RDP vulnerabilities to infiltrate systems, installing malware and RDPWrap for continuous remote access. They also deployed keyloggers to record user inputs. The group has been targeting 's software, energy, and financial industries since October 2023, with attacks extending to multiple countries worldwide. Their methods include exploiting the vulnerability () and using emails. The attackers employ various tools such as RDP scanners, droppers, and keyloggers in their multi-stage attack process.

External references