ESTsecurity (CEO Jung Jin-il), a security specialist, said on the 9th that a North Korea-linked hacking attack based on a malicious
HWP document, disguised as an exercise gathering opinions from North Korean defector advisory members, has been found, and that particular care is required.
What characterizes this attack is that it was disguised as an opinion-gathering questionnaire for North Korean defector advisory members.
The attacker abused the OLE (object linking and embedding) function inside the HWP document, and when the document runs it displays a fake message window reading 'This document was created in a higher version'
and similar content, to induce a natural click.
That message window is something users see often in HWP documents, and clicking the [OK] button without particular suspicion exposes them directly to the hacking attack. According to analysis by ESTsecurity's Security Response Center (ESRC), a malicious OLE file is embedded inside the HWP, and the analysis also confirmed a function inside the OLE that uses batch (BAT) files and PowerShell commands to attempt communication with a particular Korean server, 'hanainternational[.]net'.
In particular, when attempting to communicate with the command-and-control (C2) server, it was found to add operating conditions to the task scheduler that work like a dormancy function, to hide external exposure as far as possible, and to use a technique of disguising itself as an ESTsoft program.
The Fighters for a Free North Korea, meanwhile, claimed to have released around one million leaflets to North Korea using 20 large balloons in the Gimpo area of Gyeonggi Province over two days on April 25 and 26; this malicious file was used in a timely way for the attack by posing as an exercise gathering opinions on that subject.
It is worth noting this cyber threat strategy of borrowing content already reported in the media in order to maximize the attack's effect.
ESRC found that, as with February's phishing attack impersonating the UN Human Rights Office, this attack also used a Korean server as an intermediate base for the hack, and that the same task scheduler name and the IDs 'PEACE' and 'Lailey' were used in common.
OLE-based attacks like this one, which do not use an HWP vulnerability as such, are still reported from time to time; because no security vulnerability is involved, all Hancom Office users — from older products to the very latest version — need to be more careful when they see a separate message window prompting a click.
The HWP attack technique and tactical commands used here in particular were analyzed as matching earlier North Korea-linked cyberattacks, and a North Korean cyber threat group was identified as being behind it. ESRC Director Moon Jong-hyun said: "Spear phishing attacks based on malicious HWP documents have declined a great deal compared with the past, but they are one threat that cannot be ignored, still seen steadily in covert targeted attacks," adding, "Because North Korea-linked cyber threats are growing by the day like this, closer public-private coordination and cooperation matters."
ESTsecurity's ESRC, meanwhile, is closely sharing related cyber threat information with the Korea Internet & Security Agency (KISA) and other relevant authorities, maintaining cooperation to prevent known threats from spreading.