Categories: All

North Korea Hacks Into Word Processor Used by South Korean Government

According to the security firm FireEye, Hangul Word Processor program used by the South Korean government was recently hacked by North Korean hackers. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server.


he word processor program called Hangul Word Processor is one of the most used programs by the South Korean government and public institutions. According to a report by FireEye, North Korean hackers have reportedly hacked into this popular word processor program used by the South Korean government.
Few days ago, a vulnerability CVE-2015-6585 was reported and patched by its developer Hancom. The security firm examined the vulnerability and told that a group of hackers used the flaw in software to send and receive encrypted documents.

This 0-day exploit, used a .hwpx document, that helped to infect the Hangul Word Processor and opened a backdoor in the same. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server. The HANGMAN backdoor is finely crafted as it used SSL to encrypt the communications it made with C&C server.
FireEye researchers said: “The backdoor also wraps its communication protocol with SSL. HANGMAN begins communications by sending a legitimate SSL handshake to its command and control (C2) server. It then continues to communicate using SSL header messages, but the payload of the message is a custom binary protocol.”
However, the firm didn’t directly confirm the involvement of North Korea. It attributed the hack to North Korea as the backdoor made use of an IP address earlier spotted in another backdoor called MACKTRUCK. Also, the HANGMAN code was similar as seen in PEACHPIT and MACKTRUCK backdoors. It should be noted that these older backdoors were linked to North Korean government.
FireEye writes: “Both PEACHPIT and HANGMAN incorporate a function where Windows commands are passed to the backdoor from the remote C2 server. ”

Did you like this story? Tell your views in comments below.
spatsariya

Share
Published by
spatsariya

Recent Posts

Still Not Using Razer Gold? Let’s Fix That

Look, if you’re not using Razer Gold yet, we need to talk. It’s 2025, and…

2 hours ago

New HP EliteBook, ProBook, and OmniBook Models Launched in India

HP has introduced a new series of AI-based laptops in India, aimed at professionals and…

1 day ago

Why Parents Prefer Xbox Gift Cards Over Credit Cards for Their Kids’ Gaming Purchases

Ah, parenting in 2025. Once, the biggest fear was your kid ordering 12 pizzas by…

1 day ago

Best Racing Games for PS5 Ranked (April 2025)

If you’re a motorsport fan, racing games are probably the closest you’ll ever get to…

1 day ago

What is 3D Printing & How Does a 3D Printer Work?

Until a few years ago, 3D printing was just an expensive hobby for enthusiasts. However,…

1 day ago

How Video Games Are Redefining Modern Storytelling

Narrative-driven games aren’t new, but what they’re doing now is. We’ve gone way past “games…

2 days ago