Open-source malware research tied multiple intrusions against financial organizations to a cluster of PowerShell- and document-based tooling associated with North Korean operators, while also surfacing possible overlap with activity commonly tracked as TA505. Analysts described a previously undisclosed PowerShell backdoor dubbed PowerBrace in investigations of 2018 SWIFT-heist activity, alongside reporting that mixed DPRK indicators, TA505 indicators, and closely related PowerShell scripts in attacks on banks. Separate analysis also documented PSLogger, a keylogging and screen-capture utility linked to attempted intrusions against financial targets in Vietnam, with variants delivered through a modified PowerSploit framework and a standalone executable sharing the same codebase.
Additional technical work examined a malicious Hangul Word Processor (.hwp) document attributed to a DPRK threat actor, showing a zlib-compressed EPS object that unpacked shellcode, launched a suspended Internet Explorer process, injected code, and contacted a compromised Korean website for follow-on payload delivery. Based on code and infrastructure overlap, the likely final payload was assessed as NavRAT or a closely related family. Together, the reporting portrays a financially focused intrusion set using commodity code reuse, PowerShell backdoors, keylogging utilities, and weaponized documents, while leaving open the possibility that some activity attributed to TA505 and DPRK operators may intersect or share tooling.

See the actors and campaigns active against you right now.
9 events from the most recent confirmed update back to the earliest known activity.
At SAS2019, BAE Systems presented research on DPRK-linked SWIFT heist activity from 2018. The findings included a previously undisclosed PowerShell backdoor later dubbed PowerBrace and suggested possible overlap with TA505 intrusions.
A user identified as fabd7a52 in Pakistan first uploaded the standalone keylogger sample HSMBalance.exe, which shared code and behavior with the Vietnam PSLogger malware. Norfolk InfoSec used this as evidence of a related intrusion set extending beyond the Vietnam case.
Norfolk InfoSec published research on a previously undisclosed DPRK-attributed PowerShell backdoor dubbed PowerBrace and examined possible overlap between TA505 and DPRK intrusions. The post also released selected indicators and analysis linking PSLogger, PowerBrace-related samples, and financial-sector targeting.
Norfolk InfoSec dissected the malicious HWP document's EPS and shellcode stages, showing process injection into Internet Explorer and follow-on network execution logic. Based on overlap with Cisco Talos reporting, the author assessed the likely final payload as NavRAT or a close relative.
ESTsecurity reported a newly identified malicious Hangul Word Processor document sharing technical characteristics with activity attributed to North Korean threat actors. The sample used EPS-embedded shellcode to launch Internet Explorer and contact a compromised Korean website.
Norfolk InfoSec published analysis of the PSLogger keylogger and screen-capture utility, linking Vietnam and Pakistan samples through shared code, paths, and behavior. The post assessed the activity as consistent with North Korean financial-sector operations.
In early January, VNCert issued an alert on attacks targeting financial institutions that mixed DPRK and TA505 indicators. The alert included the PSLogger keylogger and PowerShell artifacts later assessed as related to DPRK activity.
A VNCert report in late July included file-based indicators tied to attempted intrusions against financial organizations in Vietnam. The alert identified a DLL-based keylogger delivered via a modified PowerSploit framework.
360 TIC reported that TA505 recently targeted financial institutions using Excel 4.0 macro lures. Norfolk InfoSec later cited this reporting as overlapping with TA505 indicators seen in the same month.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
sec0wn.blogspot.com
Open sourcesec0wn.blogspot.com
Open sourcenorfolkinfosec.com
Open sourcenorfolkinfosec.com
Open sourcenorfolkinfosec.com
Open sourceti.360.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.