Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Analysis of a Phishing Email Attack Case

0
Medium
Published: 08/03/2026 (08/03/2026, 16:50:56 UTC)
Source: AlienVault OTX General

Description

The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023 targeting Korean and global users. The attacks use LNK files disguised as documents on topics like hospital surveys and resumes to deliver malware. Execution triggers obfuscated PowerShell commands that deploy backdoors and download additional scripts. The attack chain includes persistence via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Their Notifier malware version 2.1 uses the Telegram API for status reporting. These campaigns show consistent tactics and infrastructure over multiple years.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 09:37:03 UTC

Technical Analysis

Larva-24009 (HeptaX) operates phishing campaigns using LNK files to deliver malware that executes obfuscated PowerShell commands. These commands deploy backdoors and download further scripts from command-and-control servers. The threat actor establishes persistence via Windows Task Scheduler and enables remote access using QuasarRAT and UltraVNC. Information theft is conducted with NirSoft utilities, custom keyloggers, and screenshot tools. The actor also creates backdoor RDP accounts and exfiltrates sensitive data including credentials and browser information. Notifier malware version 2.1 reports status via Telegram API. The campaigns have targeted enterprises globally since 2023 and remain active through 2026, demonstrating consistent tactics and infrastructure.

Potential Impact

Successful exploitation results in remote access to victim systems, persistent backdoors, credential theft, browser data exfiltration, user file theft, and monitoring via keyloggers and screenshots. The attacker can maintain long-term access and control, potentially leading to significant data compromise and operational disruption.

Mitigation Recommendations

No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on user awareness to identify and avoid phishing emails with LNK attachments, restrict execution of LNK files from email or untrusted sources, monitor for suspicious PowerShell activity, and detect use of known tools such as QuasarRAT, UltraVNC, and NirSoft utilities. Implementing application whitelisting and endpoint detection can help mitigate infection. Refer to the vendor advisory at https://asec.ahnlab.com/en/94786/ for detailed detection and response guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://asec.ahnlab.com/en/94786/"]
Adversary
Larva-24009
Pulse Id
6a70c6f0d15cdde2874f628e
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpozeny.shop
domainaonexa.shop
domainmainsec.site
domainserverdock.online
domainfinal.mainsec2.site

Ip

ValueDescriptionCopy
ip217.77.6.50

Hash

ValueDescriptionCopy
hash10b40185106eb3760cb71c46117aa0bf
hash1500fefcdda275b70e2051a3e7d9f794
hash2973fda8d0d0fa0200a05889fce85df6
hash444fb3592cd1848660259a913684795b
hash4ad28d0313549e98383144d82982be6e

Threat ID: 6a71a3ffbf32cb7a3406dcf8

Added to database: 08/04/2026, 08:34:07 UTC

Last enriched: 08/04/2026, 09:37:03 UTC

Last updated: 08/04/2026, 09:37:03 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses