Shares tags: Wateringhole, IPUS • Same author: Ahnlab • Published within a week
통일 교육 지원서로 위장한 악성 한글 문서
2025-03-13 • Ahnlab • Malicious Hangul Document Disguised as an Application for Unification Education Support •
AhnLab reports a malicious HWP document distributed through a unification education application post, where the downloaded file masquerades as a legitimate application form while dropping BAT, executable, manifest, and scheduled-task XML components into the temporary directory. The malware infection flow uses embedded hyperlinks and document.bat execution to rename components, maintain persistence, and make malicious activity harder for victims to notice.
Related Reports
Shares tags: Wateringhole, IPUS • Published within a week
Shares tag: Wateringhole • Same author: Ahnlab
Shares tag: Wateringhole • Same author: Ahnlab
Shares tag: Wateringhole • Same author: Ahnlab
Shares tag: Wateringhole