North Korea installs backdoor in South's HWP: Hackers linked to the notorious North Korean attack are exploiting a zero-day vulnerability in the Hangul Word Processor (HWP), which is widely used in South Korean government offices.
According to research by FireEye, the attackers exploited a previously known vulnerability (CVE-2015-6585) that was patched last Monday. The attack required victims to open a malicious HPWX file.
The zero-day exploit consisted of distributing a malicious .hwpx document (similar to Microsoft Office's .docx), which causes errors in the Hangul Word Processor to open a backdoor in the software.
According to FireEye, this backdoor, called HANGMAN, can steal files and upload them to a C&C server, while also being able to download new files from the victim's computer.
The HANGMAN is very well designed, uses SSL to encrypt its communication with the C&C server, hiding the data transfer from prying eyes.
What HANGMAN betrayed was that during communication with the C&C server, the backdoor used an IP address that had previously been detected in a previous backdoor, MACKTRUCK.
Also, some of the functions that were used in the HANGMAN code resembled some that had been used in PEACHPIT.
From’ the moment that PEACHPIT and MACKTRUCK had already been identified in campaigns that had a common target and interest around South Korea, linking the three attacks to the Pyongyang government was relatively easy.
