Security researchers reported multiple spearphishing campaigns using malicious Hangul Word Processor (HWP) files themed around North Korea, peace, reunification, and event questionnaires to target Korean-speaking users. The lures included files such as 1_참가신청서.hwp and 질의서-12월15일.hwp, some masquerading as legitimate government or broadcast-related documents. In several cases, the documents abused OLE functionality rather than a software exploit, relying on user interaction with a transparent object or hyperlink to extract and launch an embedded executable such as HncApp.exe from the Temp directory.
The malware then executed staged payloads, established persistence by copying itself into public document paths and creating Run registry entries, and contacted command-and-control infrastructure including price365.co[.]kr/abbi/json/ps/aa.php and yegip.kr for follow-on instructions. Analysts said one sample used batch files including TroubleShooter.bat and Diagnostics.bat, while others decoded additional payloads with XOR and loaded secondary malware into memory for remote control, information theft, and possible screenshot exfiltration. Researchers linked the infrastructure and tradecraft to previously reported North Korea-linked APT activity, noting that the technique abuses legitimate document behavior and can remain effective even on fully patched systems.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
AhnLab said V3 added detection coverage for the questionnaire-themed HWP sample, its batch component, and its script component. The cited engine version was 2021.04.09.04.
A later ASEC analysis said the malicious file '질의서-12월15일.hwp' appeared to have been modified from a real questionnaire used for a North Korea-related broadcast discussion on December 15, 2020. This indicates attackers repurposed a legitimate document as social-engineering bait.
Metadata for '1_참가신청서.hwp' shows the file was last modified by 'Julias Cesar'. The modified document contained the malicious OLE object used to launch the embedded executable.
The malicious executable embedded in the HWP OLE object, 'HncApp.exe', had a compile timestamp of 2020-12-05 09:19:45 KST. This executable was the first-stage payload triggered by user interaction with the document.
The decoded payload embedded in the HWP-delivered malware carried a timestamp indicating it was built before the campaign was launched. The payload was later loaded into memory after XOR decoding.
ESRC published analysis of a December 2020 spearphishing campaign using the attachment '1_참가신청서.hwp' and a transparent object to trigger an embedded executable via normal OLE behavior. The report described persistence through the 'IDMhelp' Run key and C2 communications with price365.co[.]kr, and assessed the activity as consistent with a North Korea-linked APT group.
ESRC disclosed a malicious HWP document themed around U.S. presidential election predictions that abused Hancom Office OLE functionality to run embedded VBS and staged HTA/PowerShell payloads via xeoskin.co[.]kr. The report attributed the activity to Thallium/Kimsuky based on reused infrastructure paths, multipart boundary strings, and the mutex name "Global\\AlreadyRunning191122".
Metadata for the HWP lure file '1_참가신청서.hwp' shows it was created with author 'user'. This file was later used in a spearphishing campaign abusing HWP OLE functionality.
ASEC reported increased distribution of malicious HWP files using North Korea-related questionnaire themes, including '질의서-12월15일.hwp'. The analysis described a linked-object execution chain through TroubleShooter.bat, Diagnostics.bat, and HncConfig.ini that attempted to fetch remote content from yegip.kr.
AhnLab stated V3 detected the malicious HWP and Windows payload associated with the peace-themed campaign as 'Dropper/HWP.Agent' and 'Trojan/Win32.Agent.C4251645'. The signature version cited in the report was 2020.12.09.00.
ASEC disclosed an active campaign distributing a forged peace and reunification-themed HWP document that dropped 'HncApp.exe', established persistence as 'IDMhelpAssist.exe', and contacted the C2 URL price365.co[.]kr. The report linked the infrastructure to prior RedEyes APT activity and published related IOCs and detections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceblog.alyac.co.kr
Open sourceasec.ahnlab.com
Open sourceblog.alyac.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.