대북 관련 한글문서(HWP) 유포 중

2021-12-24 Ahnlab Disseminating Hangul documents (HWP) related to North Korea

https://asec.ahnlab.com/ko/30149/

Thumbnail for 대북 관련 한글문서(HWP) 유포 중

AhnLab reports malicious Hangul Word Processor documents themed around North Korea-related construction activity that rely on embedded objects and a user-clicked hyperlink rather than an exploit. When the lure is opened and clicked, a legitimate OneDrive updater side-loads a malicious iphlpapi.dll, decodes embedded payloads into AppData, hides V3 detection windows, and registers a scheduled task to run every 121 minutes. The chain moves VBS and PowerShell components into the user profile, displays a benign HWP decoy, and retrieves attacker-controlled instructions through Google Drive and Google Docs, allowing later commands against infected hosts. The report highlights the continued use of HWP lures in Korea-focused activity and lists detections including Dropper/HWP.HyperLink and Trojan/Win.Kimsuky.C4848645.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a7077d9a2c98ec2d0b3b1c12f23b2a79 2021-12-24 2025-04-01
HASH a532a4fe38b76f53885158aa3b75e5dc 2021-12-24 2021-12-24
HASH 8ec6e4d3a6142b8bde35899e7fdae42e 2021-12-24 2021-12-24
HASH 3c45e0def2845cc130a9331c774d3935 2021-12-24 2021-12-24
HASH 41aca1d4282dfb41356ee95e933eedc1 2021-12-24 2021-12-24

Related Actors

Related Reports

« Back