Targeted Attacks on South Korean Organizations: Attacks Using Local Word Processor
2018-03-23 • Ahnlab •
http://global.ahnlab.com/global/upload/download/techreport/Tech_Report_Malicious_Hancom.pdf
Attachments
AhnLab examined malicious Hangul Word Processor files used against South Korean organizations from September 2016 through December 2017. The targets were mainly employees of North Korea related businesses and virtual currency businesses, with delivery through email attachments or download links. The report describes HWP vulnerability, EPS, script, and embedded object techniques, noting a shift toward memory execution after September 2016 to evade behavior based detection. AhnLab grouped the activity into three attacker clusters, two of which actively used Hangul files as a delivery mechanism.