216.73.216.226

Case of Larva-25004 Group (Related to Kimsuky) Exploiting Additional Certificate - Malware Signed with Nexaweb Certificate

· Published 23/05/2025 20:17 · Modified 23/05/2025 22:05

Export JSON

Essential information

Published
23/05/2025 20:17
Modified
23/05/2025 22:05
Tags
2025-05-23 certificate exploitation certificate leak kimsuky nexaweb signed malware
Related entities
3 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 1 others

Description

AhnLab Security Intelligence Center discovered malware signed with Inc.'s certificate, linked to the group's activities. The malware, tracked as Larva-25004, was found in two files signed on May 24 and 28, 2024. When executed, it displays a PDF file related to employment as bait, likely targeting individuals interested in defense company jobs. The certificate's authenticity is still under investigation. The malware's characteristics match those of files signed with a Korean company's certificate, previously reported in connection with . This incident highlights the ongoing threat of by sophisticated threat actors.

External references