Case of Larva-25004 Group (Related to Kimsuky) Exploiting Additional Certificate - Malware Signed with Nexaweb Certificate
Essential information
- Published
- 23/05/2025 20:17
- Modified
- 23/05/2025 22:05
- Tags
- 2025-05-23 certificate exploitation certificate leak kimsuky nexaweb signed malware
- Related entities
- 3 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 1 others
Description
AhnLab Security Intelligence Center discovered malware signed with Nexaweb Inc.'s certificate, linked to the Kimsuky group's activities. The malware, tracked as Larva-25004, was found in two files signed on May 24 and 28, 2024. When executed, it displays a PDF file related to employment as bait, likely targeting individuals interested in defense company jobs. The certificate's authenticity is still under investigation. The malware's characteristics match those of files signed with a Korean company's certificate, previously reported in connection with Kimsuky. This incident highlights the ongoing threat of certificate exploitation by sophisticated threat actors.