Proprietary · · 30 days

A Korean ERP updater stole data

A South Korean ERP updater was modified to launch Xctdoor through Regsvr32. ASEC linked the method to Andariel-style ERP update abuse against Korean companies.

ASEC described a May 2024 attack against Korean companies in defense and manufacturing. The attacker appears to have abused a Korean ERP update server, then used the ERP update program as the trusted local execution path.

The changed program was ClientUpdater.exe. In the older 2017 pattern, Andariel inserted downloader logic into the ERP updater to fetch HotCroissant. In the 2024 case, ASEC saw a simpler routine that executed a DLL from a specific path with Regsvr32.exe.

The payload was Xctdoor, a Go DLL backdoor named from strings such as XctMain. It injected into processes including taskhost.exe, taskhostex.exe, taskhostw.exe, and explorer.exe, copied itself to an Edge package settings path as roaming.dat, and installed startup persistence.

This record stays scoped to the ERP update path. Public reporting did not prove a broad customer compromise or publish victim counts, but it did identify the affected mechanism, payload family, and Korean industrial target set.

Notes

  • All 23 digests on this record were corroborated on 2026-09-02 and none is in doubt, which is worth stating because sixteen are unknown to MalwareBazaar, Triage and VirusTotal alike.
  • That silence is about where the samples live: twenty appear verbatim in the archived AhnLab ASEC pages, and the remaining three SHA-256s are known to VirusTotal with 44 or 45 engines detecting them, one named icsvcext.dll.
  • A Korean vendor's IOCs being absent from Western sample repositories is the expected case, not a sign of bad metadata.

Appendix · Affected releases

ClientUpdater.exe ksystem updater

References

  1. KSystem's own 2018 notice about its separate December 2017 breach, cited by ASEC as a past caseblog.ksystem.co.kr
  2. Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)asec.ahnlab.com
  3. Xctdoor Malware Used in Attacks Against Korean Companies (Andariel) - Koreanasec.ahnlab.com
  4. South Korean ERP Vendor's Server Hacked to Distribute Xctdoor Malwarethehackernews.com

Source record: proprietary/ksystem/meta.yaml