ASEC analyzes the connection between Xctdoor backdoor and historical CRAT malware attacks by Larva-26005, a North Korea-linked threat actor targeting Korean users since at least 2020. Xctdoor and CRAT share identical code obfuscation routines, XOR decryption algorithms, and AppX package installation paths. The threat actor uses spear phishing LNK files, disguised security software, compromised web servers, and tampered ERP/groupware update modules for initial access, deploying XcLoader as an injector and Xctdoor as a full-featured backdoor with capabilities including shell execution, file exfiltration, keylogging, and process injection.
CRAT
2 posts
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) ASEC identifies the Larva-26005 threat actor (linked to North Korea's Lazarus group) as actively distributing the Xctdoor backdoor to Korean users through spear phishing LNK files and disguised security software installers. The analysis establishes a direct connection between Xctdoor and the CRAT backdoor (active since 2020), noting shared code obfuscation routines, identical AppX package installation paths, and historical co-deployment with Hansom ransomware. The attack chain leverages DLL side-loading, multi-stage script downloaders (VBS/BAT/PS1), XOR-encrypted payloads, and process injection via RegSvr32 to deliver a full-featured backdoor supporting shell sessions, keylogging, screenshots, file exfiltration, and in-memory payload injection.