Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023 targeting Korean and global users. The attacks use LNK files disguised as documents on topics like hospital surveys and resumes to deliver malware. Execution triggers obfuscated PowerShell commands that deploy backdoors and download additional scripts. The attack chain includes persistence via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Their Notifier malware version 2.1 uses the Telegram API for status reporting. These campaigns show consistent tactics and infrastructure over multiple years.
AI Analysis
Technical Summary
Larva-24009 (HeptaX) operates phishing campaigns using LNK files to deliver malware that executes obfuscated PowerShell commands. These commands deploy backdoors and download further scripts from command-and-control servers. The threat actor establishes persistence via Windows Task Scheduler and enables remote access using QuasarRAT and UltraVNC. Information theft is conducted with NirSoft utilities, custom keyloggers, and screenshot tools. The actor also creates backdoor RDP accounts and exfiltrates sensitive data including credentials and browser information. Notifier malware version 2.1 reports status via Telegram API. The campaigns have targeted enterprises globally since 2023 and remain active through 2026, demonstrating consistent tactics and infrastructure.
Potential Impact
Successful exploitation results in remote access to victim systems, persistent backdoors, credential theft, browser data exfiltration, user file theft, and monitoring via keyloggers and screenshots. The attacker can maintain long-term access and control, potentially leading to significant data compromise and operational disruption.
Mitigation Recommendations
No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on user awareness to identify and avoid phishing emails with LNK attachments, restrict execution of LNK files from email or untrusted sources, monitor for suspicious PowerShell activity, and detect use of known tools such as QuasarRAT, UltraVNC, and NirSoft utilities. Implementing application whitelisting and endpoint detection can help mitigate infection. Refer to the vendor advisory at https://asec.ahnlab.com/en/94786/ for detailed detection and response guidance.
Indicators of Compromise
- domain: pozeny.shop
- ip: 217.77.6.50
- hash: 10b40185106eb3760cb71c46117aa0bf
- hash: 1500fefcdda275b70e2051a3e7d9f794
- hash: 2973fda8d0d0fa0200a05889fce85df6
- hash: 444fb3592cd1848660259a913684795b
- hash: 4ad28d0313549e98383144d82982be6e
- domain: aonexa.shop
- domain: mainsec.site
- domain: serverdock.online
- domain: final.mainsec2.site
Analysis of a Phishing Email Attack Case
Description
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023 targeting Korean and global users. The attacks use LNK files disguised as documents on topics like hospital surveys and resumes to deliver malware. Execution triggers obfuscated PowerShell commands that deploy backdoors and download additional scripts. The attack chain includes persistence via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Their Notifier malware version 2.1 uses the Telegram API for status reporting. These campaigns show consistent tactics and infrastructure over multiple years.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Larva-24009 (HeptaX) operates phishing campaigns using LNK files to deliver malware that executes obfuscated PowerShell commands. These commands deploy backdoors and download further scripts from command-and-control servers. The threat actor establishes persistence via Windows Task Scheduler and enables remote access using QuasarRAT and UltraVNC. Information theft is conducted with NirSoft utilities, custom keyloggers, and screenshot tools. The actor also creates backdoor RDP accounts and exfiltrates sensitive data including credentials and browser information. Notifier malware version 2.1 reports status via Telegram API. The campaigns have targeted enterprises globally since 2023 and remain active through 2026, demonstrating consistent tactics and infrastructure.
Potential Impact
Successful exploitation results in remote access to victim systems, persistent backdoors, credential theft, browser data exfiltration, user file theft, and monitoring via keyloggers and screenshots. The attacker can maintain long-term access and control, potentially leading to significant data compromise and operational disruption.
Mitigation Recommendations
No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on user awareness to identify and avoid phishing emails with LNK attachments, restrict execution of LNK files from email or untrusted sources, monitor for suspicious PowerShell activity, and detect use of known tools such as QuasarRAT, UltraVNC, and NirSoft utilities. Implementing application whitelisting and endpoint detection can help mitigate infection. Refer to the vendor advisory at https://asec.ahnlab.com/en/94786/ for detailed detection and response guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/en/94786/"]
- Adversary
- Larva-24009
- Pulse Id
- 6a70c6f0d15cdde2874f628e
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpozeny.shop | — | |
domainaonexa.shop | — | |
domainmainsec.site | — | |
domainserverdock.online | — | |
domainfinal.mainsec2.site | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip217.77.6.50 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash10b40185106eb3760cb71c46117aa0bf | — | |
hash1500fefcdda275b70e2051a3e7d9f794 | — | |
hash2973fda8d0d0fa0200a05889fce85df6 | — | |
hash444fb3592cd1848660259a913684795b | — | |
hash4ad28d0313549e98383144d82982be6e | — |
Threat ID: 6a71a3ffbf32cb7a3406dcf8
Added to database: 08/04/2026, 08:34:07 UTC
Last enriched: 08/04/2026, 09:37:03 UTC
Last updated: 08/04/2026, 09:37:03 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.