← Back to Feed

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

August 3, 2026 · AhnLab ASEC · Severity: HIGH

This article analyzes the connection between Xctdoor and past CRAT attack cases. AhnLab's ASEC confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. The malware was previously disclosed in 2024 and later disguised as a security program in a March 2026 attack.

Key Takeaways

  • Larva-26005 threat actor distributes Xctdoor to Korean users.
  • Xctdoor was first disclosed by ASEC in 2024.
  • In March 2026, Xctdoor was disguised as an integrated security program.
☕ Buy a Coffee