The official Korean Central News Agency (KCNA) website was used in a watering-hole attack that delivered a malicious ZIP archive disguised as an Adobe Flash Player update to Windows visitors. Systems without Flash Player 10 or newer were redirected to the fake installer, which deployed components including mscaps.exe and wtime32.dll, established persistence, injected into processes, stole system and user data, and communicated with multiple command-and-control servers.
The malware also spread beyond the initial compromise by infecting local files, network shares, and removable media, enabling broader propagation inside organizations. Telemetry linked infections primarily to China, South Korea, and Russia, with some detections involving DPRK-linked systems, while researchers said direct attribution to North Korea remained unproven because the KCNA site appeared to have an XSS weakness that could have been abused by another actor; the operation nevertheless showed several similarities to DarkHotel, including spoofed Flash installers, victim profiling, and multi-domain C2 infrastructure.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A record attributed to Hexspirit documenting the KCNA site's XSS weakness was posted on XSSed in April 2013. This public record is cited as supporting evidence that the site could have been compromised by a third party.
The KCNA website was reportedly vulnerable to cross-site scripting in early 2013, creating a plausible avenue for an external actor to place the malware bundle on the site. The analysis cites this as a reason not to assume DPRK developers directly ran the operation.
The malware components associated with the campaign, including mscaps.exe and wtime32.dll, were first detected in November 2012. This predates the first known appearance of the FlashPlayer malware bundle on the KCNA website.
The official KCNA website served a malicious ZIP archive disguised as a Flash Player update to some Windows visitors lacking Flash Player 10 or newer. The archive delivered executables using common Flash installer names and was described as the only known source of that malware bundle.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.