← Back to Feed
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
August 3, 2026 · AhnLab ASEC · Severity: HIGH
This article analyzes the connection between Xctdoor and past CRAT attack cases. AhnLab's ASEC confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. The malware was previously disclosed in 2024 and later disguised as a security program in a March 2026 attack.
Key Takeaways
- Larva-26005 threat actor distributes Xctdoor to Korean users.
- Xctdoor was first disclosed by ASEC in 2024.
- In March 2026, Xctdoor was disguised as an integrated security program.