윈도우 도움말 파일(CHM)악용 해킹수법 주의 권고
2024-04-02 • KRCERT • CHM : Microsoft Compiled HTML Help •
https://www.krcert.or.kr/kr/bbs/view.do?bbsId=B0000133&pageIndex=1&nttId=71390&menuNo=205020
KRCERT warns that hacking groups are abusing Microsoft Compiled HTML Help files in malicious email campaigns. The source says attackers use North Korea-related questionnaire themes to attract targets, then induce recipients to open attached CHM files. When opened, the help content appears normal while the malware body installs in the background, hiding the compromise from the user. The advisory recommends avoiding files from unclear sources, keeping systems and antivirus tools updated, refraining from opening CHM email attachments, and reporting incidents through Boho or the 118 cyber civil complaint center.