Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

DOKKAEBI: Documents of Korean and Evil Binary

released on 2018-08-01 @ 02:34:32 AM
Dokkaebi is frequently disguised as a legitimate organization or company in order to lure its targets. Once the HWP malware is executed, it acts in an insidious way. HWP malware is very well known and is mentioned in many threat intelligence reports. This kind of malware has long been used in spear-phishing attacks due to the fact that the South Korean government and many public organizations have, for many years, used Hangul Word Processor (a.k.a HWP) as their official documentation software. The interesting part regarding HWP malware is that the payload dropped from this malware is related to well-known malware families and threat groups such as Scarcruft (Group123, Reaper), Bluenoroff, Kimsuky and so on. These malicious payloads have also been observed in several incidents targeting cryptocurrency exchanges located in many other countries as well as in South Korea.