활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송)
2022-06-10 • Ahnlab • Malicious Korean documents containing BAT scripts being actively distributed (North Korea/Defense/Broadcasting) •
AhnLab observed an active wave of malicious Hangul Word Processor documents targeting defense, North Korea-related, and broadcasting personnel. The documents abused HWP's OLE object-linking feature to drop and run BAT scripts after user clicks, then launched PowerShell that decoded shellcode and injected it into the legitimate Windows help.exe process. Filenames and lures included defense conference material, North Korea COVID-19 analysis, applications, resumes, and education-related documents distributed through PC messengers and web browser downloads. Code similarities and reused PowerShell variable names matched an earlier malicious HWP case, and the excerpt labels the malware family as Infostealer/PS.Kimsuky with multiple MD5 indicators. The activity matters because it shows attackers shifting from patched PostScript/EPS exploit paths to user-assisted OLE execution that can still affect updated Hancom Office environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 404e2fe1fbca70603cb91932664bc112 | 2022-06-10 | 2022-06-10 |
| HASH | e223711e31431250946203c27372cd3a | 2022-06-10 | 2022-06-10 |
| HASH | 7dea7277f672ad85fdf344c467f739eb | 2022-06-10 | 2022-06-10 |
| HASH | 546ae7bd8b88289a21ac8d7dc62a3bd7 | 2022-06-10 | 2022-06-10 |
| HASH | 7442a74c7351b8ab0bb49b778530a95e | 2022-06-10 | 2022-06-10 |
| HASH | 393f78e609af5e77da5ea9ba10facbfb | 2022-06-10 | 2022-06-10 |
| HASH | b5b0ffecc4b30e7f140b517333c6a2d2 | 2022-06-10 | 2022-06-10 |
| HASH | 390a2439581b8c04adace93fed2e4425 | 2022-06-10 | 2022-06-10 |
| HASH | 1d413a7c62b48760838bed0d03a35b05 | 2022-06-10 | 2022-06-10 |
| HASH | 667dbfdc01cc6e808b2485c7eed74e97 | 2022-06-10 | 2022-06-10 |
| HASH | 9aac95c3d76319fe3df9fed53fb06507 | 2022-06-10 | 2022-06-10 |
| HASH | 882546e8fc2dc2fd580170afda20e396 | 2022-06-10 | 2022-06-10 |
| HASH | 87c1f6ab7933bce7969f593e3c6096c2 | 2022-06-10 | 2022-06-10 |