Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
AI Analysis
Technical Summary
Larva-24009 (HeptaX) operates phishing campaigns leveraging LNK files attached to emails with themes like hospital surveys and resumes to target enterprises. Execution of these files triggers obfuscated PowerShell commands that deploy backdoors and download further malicious scripts from command-and-control servers. The threat actor maintains persistence through Windows Task Scheduler and enables remote access using QuasarRAT and UltraVNC. Information theft is conducted using NirSoft utilities, custom keyloggers, and screenshot tools. Additionally, the actor creates backdoor RDP accounts and exfiltrates sensitive data including credentials and browser information. Notifier malware version 2.1 communicates status updates via the Telegram API. These campaigns have been active since 2023 and continue through 2026, showing consistent use of tactics and infrastructure.
Potential Impact
Successful exploitation results in remote access to victim systems, persistent backdoors, credential theft, browser data exfiltration, user file theft, and monitoring via keyloggers and screenshots. The attacker can maintain long-term access and control over compromised systems, potentially leading to significant data compromise and operational disruption.
Mitigation Recommendations
No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on user awareness to identify and avoid phishing emails with LNK attachments. Restrict execution of LNK files from email or untrusted sources. Monitor for suspicious PowerShell activity and detect use of known tools such as QuasarRAT, UltraVNC, and NirSoft utilities. Implement application whitelisting and endpoint detection and response solutions to help mitigate infection. Refer to the vendor advisory at https://asec.ahnlab.com/en/94786/ for detailed detection and response guidance.
Indicators of Compromise
- domain: pozeny.shop
- ip: 217.77.6.50
- hash: 10b40185106eb3760cb71c46117aa0bf
- hash: 1500fefcdda275b70e2051a3e7d9f794
- hash: 2973fda8d0d0fa0200a05889fce85df6
- hash: 444fb3592cd1848660259a913684795b
- hash: 4ad28d0313549e98383144d82982be6e
- domain: aonexa.shop
- domain: mainsec.site
- domain: serverdock.online
- domain: final.mainsec2.site
Analysis of a Phishing Email Attack Case
Description
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Larva-24009 (HeptaX) operates phishing campaigns leveraging LNK files attached to emails with themes like hospital surveys and resumes to target enterprises. Execution of these files triggers obfuscated PowerShell commands that deploy backdoors and download further malicious scripts from command-and-control servers. The threat actor maintains persistence through Windows Task Scheduler and enables remote access using QuasarRAT and UltraVNC. Information theft is conducted using NirSoft utilities, custom keyloggers, and screenshot tools. Additionally, the actor creates backdoor RDP accounts and exfiltrates sensitive data including credentials and browser information. Notifier malware version 2.1 communicates status updates via the Telegram API. These campaigns have been active since 2023 and continue through 2026, showing consistent use of tactics and infrastructure.
Potential Impact
Successful exploitation results in remote access to victim systems, persistent backdoors, credential theft, browser data exfiltration, user file theft, and monitoring via keyloggers and screenshots. The attacker can maintain long-term access and control over compromised systems, potentially leading to significant data compromise and operational disruption.
Defensive Guidance
No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on user awareness to identify and avoid phishing emails with LNK attachments. Restrict execution of LNK files from email or untrusted sources. Monitor for suspicious PowerShell activity and detect use of known tools such as QuasarRAT, UltraVNC, and NirSoft utilities. Implement application whitelisting and endpoint detection and response solutions to help mitigate infection. Refer to the vendor advisory at https://asec.ahnlab.com/en/94786/ for detailed detection and response guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/en/94786/"]
- Adversary
- Larva-24009
- Pulse Id
- 6a70c6f0d15cdde2874f628e
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpozeny.shop | — | |
domainaonexa.shop | — | |
domainmainsec.site | — | |
domainserverdock.online | — | |
domainfinal.mainsec2.site | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip217.77.6.50 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash10b40185106eb3760cb71c46117aa0bf | — | |
hash1500fefcdda275b70e2051a3e7d9f794 | — | |
hash2973fda8d0d0fa0200a05889fce85df6 | — | |
hash444fb3592cd1848660259a913684795b | — | |
hash4ad28d0313549e98383144d82982be6e | — |
Threat ID: 6a71a3ffbf32cb7a3406dcf8
Added to database: 08/04/2026, 08:34:07 UTC
Last enriched: 08/11/2026, 12:42:17 UTC
Last updated: 09/18/2026, 02:34:33 UTC
Views: 130
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.