Security researchers reported multiple malware campaigns that disguised executables as document files to trick users into launching backdoors. In one case, attackers used a file named "2021년 국방부 업무보고 수정.pif" that appeared to be a revised South Korean Ministry of National Defense report; when opened, it displayed a legitimate PDF while silently dropping a malicious DLL to C:\ProgramData\Intel\Driver\driver.cfg, executing it with regsvr32.exe, and creating a scheduled task named Disk0 to run every 30 minutes. The payload was identified as a downloader that contacted command-and-control infrastructure for follow-on instructions.
A separate campaign used a malicious SCR file signed with a valid certificate from a well-known Korean company and presented with a PDF-like icon to reduce suspicion. After execution, the malware opened a decoy PDF from %TEMP%, extracted a DLL named config.dat into C:\Users\Public\, launched it with rundll32.exe, and deleted the original dropper. The backdoor then established persistence either through a MicrosoftEdgeInstaller service or a registry key, decrypted embedded configuration data with RC4 when needed, and connected to its C2 server to support file transfer, process execution, screenshot capture, configuration updates, and code injection.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ASEC identified malware distribution activity on January 24, 2021 using a file named "2021년 국방부 업무보고 수정.pif" disguised as a revised Ministry of National Defense work report. The executable displayed a decoy PDF while dropping a malicious DLL, establishing persistence with a scheduled task named "Disk0," and contacting command-and-control infrastructure.
ASEC reported that the malicious DLL dropped by the defense-themed lure had a compile timestamp of January 23, 2021. The DLL was later used as a downloader component executed via regsvr32.exe.
The Alyac report provided two IOC hashes and a C2 URL for the signed backdoor malware, and said AhnLab detected it as Trojan.Dropper.611828A and Backdoor.Agent.611828A. The analysis also documented RC4-decrypted configuration handling and supported backdoor commands such as file transfer, screenshot capture, and remote execution.
Alyac reported a malware campaign distributing a malicious SCR executable signed with a valid certificate from a well-known Korean company and disguised with a PDF-like icon. The malware dropped a decoy PDF and a DLL named config.dat, launched it with rundll32.exe, established persistence via a service or registry key, and connected to a C2 server for backdoor commands.
ASEC published technical details for the campaign, including V3 detections, two MD5 hashes, and two C2 URLs. The report described the malware's use of regsvr32.exe and scheduled-task persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.