대북 관련 한글문서(HWP) 유포 중
2021-12-24 • Ahnlab • Disseminating Hangul documents (HWP) related to North Korea •
AhnLab reports malicious Hangul Word Processor documents themed around North Korea-related construction activity that rely on embedded objects and a user-clicked hyperlink rather than an exploit. When the lure is opened and clicked, a legitimate OneDrive updater side-loads a malicious iphlpapi.dll, decodes embedded payloads into AppData, hides V3 detection windows, and registers a scheduled task to run every 121 minutes. The chain moves VBS and PowerShell components into the user profile, displays a benign HWP decoy, and retrieves attacker-controlled instructions through Google Drive and Google Docs, allowing later commands against infected hosts. The report highlights the continued use of HWP lures in Korea-focused activity and lists detections including Dropper/HWP.HyperLink and Trojan/Win.Kimsuky.C4848645.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a7077d9a2c98ec2d0b3b1c12f23b2a79 | 2021-12-24 | 2025-04-01 |
| HASH | a532a4fe38b76f53885158aa3b75e5dc | 2021-12-24 | 2021-12-24 |
| HASH | 8ec6e4d3a6142b8bde35899e7fdae42e | 2021-12-24 | 2021-12-24 |
| HASH | 3c45e0def2845cc130a9331c774d3935 | 2021-12-24 | 2021-12-24 |
| HASH | 41aca1d4282dfb41356ee95e933eedc1 | 2021-12-24 | 2021-12-24 |