활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송)

2022-06-10 Ahnlab Malicious Korean documents containing BAT scripts being actively distributed (North Korea/Defense/Broadcasting)

https://asec.ahnlab.com/ko/35189/

Thumbnail for 활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송)

AhnLab observed an active wave of malicious Hangul Word Processor documents targeting defense, North Korea-related, and broadcasting personnel. The documents abused HWP's OLE object-linking feature to drop and run BAT scripts after user clicks, then launched PowerShell that decoded shellcode and injected it into the legitimate Windows help.exe process. Filenames and lures included defense conference material, North Korea COVID-19 analysis, applications, resumes, and education-related documents distributed through PC messengers and web browser downloads. Code similarities and reused PowerShell variable names matched an earlier malicious HWP case, and the excerpt labels the malware family as Infostealer/PS.Kimsuky with multiple MD5 indicators. The activity matters because it shows attackers shifting from patched PostScript/EPS exploit paths to user-assisted OLE execution that can still affect updated Hancom Office environments.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 404e2fe1fbca70603cb91932664bc112 2022-06-10 2022-06-10
HASH e223711e31431250946203c27372cd3a 2022-06-10 2022-06-10
HASH 7dea7277f672ad85fdf344c467f739eb 2022-06-10 2022-06-10
HASH 546ae7bd8b88289a21ac8d7dc62a3bd7 2022-06-10 2022-06-10
HASH 7442a74c7351b8ab0bb49b778530a95e 2022-06-10 2022-06-10
HASH 393f78e609af5e77da5ea9ba10facbfb 2022-06-10 2022-06-10
HASH b5b0ffecc4b30e7f140b517333c6a2d2 2022-06-10 2022-06-10
HASH 390a2439581b8c04adace93fed2e4425 2022-06-10 2022-06-10
HASH 1d413a7c62b48760838bed0d03a35b05 2022-06-10 2022-06-10
HASH 667dbfdc01cc6e808b2485c7eed74e97 2022-06-10 2022-06-10
HASH 9aac95c3d76319fe3df9fed53fb06507 2022-06-10 2022-06-10
HASH 882546e8fc2dc2fd580170afda20e396 2022-06-10 2022-06-10
HASH 87c1f6ab7933bce7969f593e3c6096c2 2022-06-10 2022-06-10

Related Reports

« Back