Korean Spear-Phishing Drops Xctdoor via LNK

AhnLab ASEC · High sophistication
Last updated August 6, 2026

Researchers report real-world attacks in Korea where victims are tricked into opening shortcut (LNK) files or “security software” installers that secretly install the Xctdoor backdoor. The lures use believable filenames (e.g., account statements, lease documents, resumes) and fake installers (e.g., Veraport/SoftCamp) to get users to execute the malware.

Key findings

  • Larva-26005 distributed Xctdoor to users in Korea, with campaigns observed through 2026.
  • Attackers disguised malware as legitimate security software installers (Veraport and SoftCamp) and also used LNK shortcut files as spear-phishing payloads.
  • LNK droppers display a decoy document while creating script files that download and install Xctdoor and related loader components.
  • Observed download infrastructure included hesenorm[.]info paths used to fetch encrypted payloads and scripts.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Sales, IT/helpdesk.
  • Affected industries: Corporate users (multiple functions, Korea), General consumers (Korea).
  • Attack channels: email.
  • Impersonated: Coworker or external business contact sharing a report, Security software vendor / installer package, Business partner / internal team sending routine documents.

Awareness takeaways

  • Treat .LNK (shortcut) attachments as high-risk and report them instead of opening them.
  • Be suspicious of “decoy document” behavior, if something opens but your computer acts oddly, stop and report it.
  • Do not install “security software” from compressed files or unofficial sources; installers can be disguised to side-load malware.
  • Train finance/HR/sales teams on document-themed lures (statements, refunds, resumes, contracts) because attackers reuse these themes broadly.

Red flags to watch for

  • The “document” is actually a .LNK (Windows shortcut), not a PDF/Word file
  • “Confidential”/urgency framing to push quick opening
  • Decoy document appears while background scripts run (unexpected behavior)
  • Installer arrives as a compressed file from an untrusted source
  • Unexpected DLL side-loading behavior (legit EXE + malicious DLL in same folder)
  • Creates scripts in public folders and schedules tasks (unusual for an installer)
  • Attachment is a .LNK shortcut instead of a normal document
  • Filename-only lure with no trustworthy context or expected workflow
  • Overly broad themes (accounting, legal, HR) used to match many departments
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a coworker: “***_Comprehensive Status Report_(Confidential)_26.4.4.LNK”. Looks like a secret report, right? In recent Korean attacks, that exact kind of LNK shortcut quietly installed the Xctdoor backdoor. It pops a decoy document on screen while three hidden scripts pull encrypted malware from sites like hesenorm.info. Same campaign also ships fake Veraport or SoftCamp “security installers” in compressed files. You unzip, see a legit-looking EXE next to a shady DLL, run it, and Xctdoor is in, scheduled tasks and all. Here’s the move: if an email attachment is a .LNK shortcut or a compressed “security installer,” don’t open it, report it to Security immediately so we can check it for Xctdoor.

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Chaos RAT Masquerades as Windows Update

Chaos RAT Masquerades as Windows Update

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate Chrome/Edge browser activity. The malware is delivered as a fake “Windows update” MSI and, once run, launches a browser in a special debug mode to…

July 23, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026
Tax and SSA Lures Push Stealth Malware via Cruciferra

Tax and SSA Lures Push Stealth Malware via Cruciferra

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The campaigns used familiar social-engineering themes, tax documents, U.S. Social Security Administration messages, and even bed-bug complaints,…

July 28, 2026