Categories: All

North Korea Hacks Into Word Processor Used by South Korean Government

According to the security firm FireEye, Hangul Word Processor program used by the South Korean government was recently hacked by North Korean hackers. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server.


he word processor program called Hangul Word Processor is one of the most used programs by the South Korean government and public institutions. According to a report by FireEye, North Korean hackers have reportedly hacked into this popular word processor program used by the South Korean government.
Few days ago, a vulnerability CVE-2015-6585 was reported and patched by its developer Hancom. The security firm examined the vulnerability and told that a group of hackers used the flaw in software to send and receive encrypted documents.

This 0-day exploit, used a .hwpx document, that helped to infect the Hangul Word Processor and opened a backdoor in the same. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server. The HANGMAN backdoor is finely crafted as it used SSL to encrypt the communications it made with C&C server.
FireEye researchers said: “The backdoor also wraps its communication protocol with SSL. HANGMAN begins communications by sending a legitimate SSL handshake to its command and control (C2) server. It then continues to communicate using SSL header messages, but the payload of the message is a custom binary protocol.”
However, the firm didn’t directly confirm the involvement of North Korea. It attributed the hack to North Korea as the backdoor made use of an IP address earlier spotted in another backdoor called MACKTRUCK. Also, the HANGMAN code was similar as seen in PEACHPIT and MACKTRUCK backdoors. It should be noted that these older backdoors were linked to North Korean government.
FireEye writes: “Both PEACHPIT and HANGMAN incorporate a function where Windows commands are passed to the backdoor from the remote C2 server. ”

Did you like this story? Tell your views in comments below.
spatsariya

Recent Posts

Key Drivers Behind the Surge

Nvidia has achieved an unprecedented milestone: it has become the first publicly-traded company to reach…

7 hours ago

What to Expect from Major Tech Stocks After the Bell

As the after-market session approaches, three of the largest U.S. technology firms, Microsoft, Alphabet (Google)…

7 hours ago

Major Azure Outage Hits Microsoft 365, Xbox, and Minecraft Just Before Earnings Report

Microsoft’s cloud infrastructure buckled Wednesday morning as thousands of users found themselves locked out of…

9 hours ago

Should You Buy Palantir Stock Before Nov. 3? Key Insights & Risks

The software and analytics firm Palantir Technologies Inc. finds itself at a pivotal moment. The…

9 hours ago

JPMorgan Revises Tesla Stock Price Target: Why Analysts Are Divided

When JPMorgan adjusts its Tesla target, Wall Street sits up straight like it just saw…

12 hours ago

Apple Stock Hits $4 Trillion Valuation, Joins Nvidia and Microsoft in Trillion Dollar Club

Apple hits a $4 trillion dollar valuation and becomes the third company after Nvidia and…

14 hours ago