Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab ASEC · Medium sophistication
Last updated August 3, 2026

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads more malware used for remote access and data theft. The campaign uses business-themed topics like hospital surveys, blockchain, project documents, and resumes to look legitimate.

How the attack worked

Larva-24009 sends phishing emails with attachments that look like ordinary documents but are actually shortcut (LNK) files. Filenames often include double extensions such as ".Docx.Lnk" along with version numbers or timestamps to appear routine. Once a recipient opens the file, it launches an obfuscated PowerShell command. To avoid raising suspicion, the malware drops a decoy document in the TEMP directory and opens it while simultaneously downloading additional PowerShell scripts in the background.

Those scripts install remote access tools including QuasarRAT and UltraVNC, and the actor may also rely on RDP for control. Persistence is maintained through scheduled tasks given legitimate-sounding names like Intel or GoogleUpdate, which helps the malware blend in with normal system activity. For data theft, the toolkit includes screenshot capture, keylogging, and NirSoft credential-recovery utilities, along with a notifier component that reports infection status, in some versions via the Telegram API.

Why it succeeded

The lures used business-relevant, low-friction topics: hospital surveys, blockchain project updates, project documentation, and resumes. These themes target common workflows across Human Resources, recruiting, project management, operations, and healthcare administration, where opening an attached document is routine and expected. Because the decoy document opens normally after the LNK file executes, the victim has little reason to suspect anything happened in the background.

What to watch for

  • Attachments with double extensions ending in ".Lnk", such as ".Docx.Lnk", presented as Word documents.
  • Unusually long filenames containing version numbers or timestamps.
  • Unexpected requests to open an attachment rather than share a standard document or link.
  • A document that opens normally but was preceded by an unusual attachment type.
  • Business-themed pretexts, resumes, surveys, or project files, that push urgency to open an attachment.

How to build resistance

Organizations should train employees, especially in HR, recruiting, project management, operations, and healthcare administration, to treat any "document" that actually carries a shortcut extension as suspicious and report it rather than open it. Staff should be cautious with executable files from unknown sources generally, not only attachments labeled as documents. Keeping endpoint security software updated helps reduce the chance that a malicious attachment can execute successfully even if it is opened. Encouraging a habit of reporting anything unusual after opening an attachment, even if the visible document appears normal, can help catch infections that rely on a decoy file to avoid suspicion.

Key findings

  • Phishing emails deliver LNK files disguised as document attachments; running them launches obfuscated PowerShell.
  • Decoy documents are dropped to %TEMP% and opened to reduce suspicion while additional scripts are downloaded.
  • The campaign installs remote control tools (QuasarRAT, UltraVNC) and may also use RDP for control.
  • Persistence is maintained via scheduled tasks with legitimate-looking names (e.g., Intel/GoogleUpdate).
  • Data theft tooling includes screenshots, keylogging, and NirSoft credential-recovery utilities.
  • A notifier component reports infection status, and a newer version uses the Telegram API for notifications.

Who’s being targeted

  • Commonly targeted roles: All employees, Human Resources, Recruiting, Project Management, Operations, Healthcare administration, Executive assistants.
  • Affected industries: Enterprises (multiple industries), Healthcare (hospital-themed lures mentioned).
  • Attack channels: email.
  • Impersonated: Recruiter / HR / staffing agency (NovaCX), External vendor/agency (NovaCX), Hospital/medical partner or survey organizer.

Red flags to watch for

  • Attachment is a shortcut file masquerading as a document (e.g., ends with .Lnk)
  • Filename is unusually long and includes versioning/timestamps
  • Unexpected request to open an attachment instead of sharing a normal .docx or link
  • “Docx.Lnk” indicates it is not a real Word document
  • Attachment comes from an external sender and pushes immediate opening/review
  • The file is presented as documentation but executes code when opened
  • Survey is delivered as an executable/shortcut attachment rather than a typical survey link
  • Attachment type is inconsistent with a normal document workflow
  • Unexpected email prompts opening an attachment from an unknown source
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Larva-24009?

Larva-24009 is a threat actor that AhnLab ASEC has tracked using phishing emails with malicious LNK files disguised as document attachments to compromise organizations.

How does the fake document attachment infect a system?

When the LNK file is opened it runs an obfuscated PowerShell command, drops a decoy document in the TEMP folder to appear legitimate, and downloads additional malware in the background.

What kind of lures does Larva-24009 use?

The campaign has used business-themed topics such as hospital surveys, blockchain, project documentation, and resumes to make the attachments seem credible.

What malware gets installed after the attachment is opened?

Reported tools include QuasarRAT and UltraVNC for remote access, along with NirSoft credential-recovery utilities, screenshot capture, and keylogging, plus a notifier component that reports infection status.

Read the video transcript

You get an email from “NovaCX Recruiting” saying, “Please review the attached interview Q&A update before the next interview.” Looks harmless, right? But the attachment name is the giveaway: "NovaCX_Interview_QA+Updated_20260420_162448_version_4_4.Docx.Lnk". That “.Docx.Lnk” isn’t a real Word file, it’s a shortcut that runs hidden PowerShell, drops a fake doc, and quietly installs remote control tools. Larva-24009 loves these fake “documents” for resumes, project docs, even hospital surveys. You click, a normal-looking file opens, but in the background it’s setting scheduled tasks named things like “Intel/GoogleUpdate,” grabbing screenshots, keystrokes, and saved passwords. If you ever see an attachment ending in “.LNK” or “.Docx.Lnk,” don’t open it, hit Forward, send it to Security with one line: “Possible Larva-24009 .LNK phishing.”

Similar attacks

Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026