통일 교육 지원서로 위장한 악성 한글 문서

2025-03-13 Ahnlab Malicious Hangul Document Disguised as an Application for Unification Education Support

https://asec.ahnlab.com/ko/86762/

Thumbnail for 통일 교육 지원서로 위장한 악성 한글 문서

AhnLab reports a malicious HWP document distributed through a unification education application post, where the downloaded file masquerades as a legitimate application form while dropping BAT, executable, manifest, and scheduled-task XML components into the temporary directory. The malware infection flow uses embedded hyperlinks and document.bat execution to rename components, maintain persistence, and make malicious activity harder for victims to notice.

Related Reports

« Back