Korean Spear-Phishing Drops Xctdoor via LNK

AhnLab ASEC · High sophistication
Last updated August 6, 2026

Researchers report real-world attacks in Korea where victims are tricked into opening shortcut (LNK) files or “security software” installers that secretly install the Xctdoor backdoor. The lures use believable filenames (e.g., account statements, lease documents, resumes) and fake installers (e.g., Veraport/SoftCamp) to get users to execute the malware.

Key findings

  • Larva-26005 distributed Xctdoor to users in Korea, with campaigns observed through 2026.
  • Attackers disguised malware as legitimate security software installers (Veraport and SoftCamp) and also used LNK shortcut files as spear-phishing payloads.
  • LNK droppers display a decoy document while creating script files that download and install Xctdoor and related loader components.
  • Observed download infrastructure included hesenorm[.]info paths used to fetch encrypted payloads and scripts.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Sales, IT/helpdesk.
  • Affected industries: Corporate users (multiple functions, Korea), General consumers (Korea).
  • Attack channels: email.
  • Impersonated: Coworker or external business contact sharing a report, Security software vendor / installer package, Business partner / internal team sending routine documents.

Awareness takeaways

  • Treat .LNK (shortcut) attachments as high-risk and report them instead of opening them.
  • Be suspicious of “decoy document” behavior, if something opens but your computer acts oddly, stop and report it.
  • Do not install “security software” from compressed files or unofficial sources; installers can be disguised to side-load malware.
  • Train finance/HR/sales teams on document-themed lures (statements, refunds, resumes, contracts) because attackers reuse these themes broadly.

Red flags to watch for

  • The “document” is actually a .LNK (Windows shortcut), not a PDF/Word file
  • “Confidential”/urgency framing to push quick opening
  • Decoy document appears while background scripts run (unexpected behavior)
  • Installer arrives as a compressed file from an untrusted source
  • Unexpected DLL side-loading behavior (legit EXE + malicious DLL in same folder)
  • Creates scripts in public folders and schedules tasks (unusual for an installer)
  • Attachment is a .LNK shortcut instead of a normal document
  • Filename-only lure with no trustworthy context or expected workflow
  • Overly broad themes (accounting, legal, HR) used to match many departments
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a coworker: “***_Comprehensive Status Report_(Confidential)_26.4.4.LNK”. Looks like a secret report, right? In recent Korean attacks, that exact kind of LNK shortcut quietly installed the Xctdoor backdoor. It pops a decoy document on screen while three hidden scripts pull encrypted malware from sites like hesenorm.info. Same campaign also ships fake Veraport or SoftCamp “security installers” in compressed files. You unzip, see a legit-looking EXE next to a shady DLL, run it, and Xctdoor is in, scheduled tasks and all. Here’s the move: if an email attachment is a .LNK shortcut or a compressed “security installer,” don’t open it, report it to Security immediately so we can check it for Xctdoor.

Similar attacks

Fake Transaction Receipt Emails Drop Remote Access Tool

Fake Transaction Receipt Emails Drop Remote Access Tool

Researchers observed real phishing emails posing as transaction receipts to trick people into opening a PDF attachment. The PDF claims an “Adobe Flash Player update is required,” leading victims to download and run a script that silently installs ScreenConnect for persistent remote access.

August 18, 2026
“Quote Review” Email Drops PhantomStealer

“Quote Review” Email Drops PhantomStealer

AhnLab reported a real phishing email campaign that pretends to be a sales representative asking the victim to review and revise a quote and verify product versions. The email includes a malicious compressed attachment that leads to an executable which ultimately installs PhantomStealer, an…

August 18, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Chaos RAT Masquerades as Windows Update

Chaos RAT Masquerades as Windows Update

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate Chrome/Edge browser activity. The malware is delivered as a fake “Windows update” MSI and, once run, launches a browser in a special debug mode to…

July 23, 2026
Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026