Trend Micro reported that attackers used malicious Hangul Word Processor (HWP) document attachments to abuse embedded PostScript content and trigger code execution on victim systems. The activity relied on weaponized HWP files delivered as attachments, taking advantage of how the software handled PostScript data to run attacker-controlled code when the document was opened.
The report highlights a document-based intrusion technique aimed at users and organizations that rely on HWP, a format widely used in South Korea. By embedding harmful PostScript in seemingly legitimate files, attackers turned routine email attachments into an infection vector, underscoring the risk posed by targeted phishing campaigns and the need to scrutinize HWP attachments as potentially dangerous active content.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing malicious email attachments that abused Hangul Word Processor and PostScript formats. The reference does not provide earlier dated events, so the publication itself is the only distinct event that can be placed on the timeline from the available content.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.