Categories: All

North Korea Hacks Into Word Processor Used by South Korean Government

According to the security firm FireEye, Hangul Word Processor program used by the South Korean government was recently hacked by North Korean hackers. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server.


he word processor program called Hangul Word Processor is one of the most used programs by the South Korean government and public institutions. According to a report by FireEye, North Korean hackers have reportedly hacked into this popular word processor program used by the South Korean government.
Few days ago, a vulnerability CVE-2015-6585 was reported and patched by its developer Hancom. The security firm examined the vulnerability and told that a group of hackers used the flaw in software to send and receive encrypted documents.

This 0-day exploit, used a .hwpx document, that helped to infect the Hangul Word Processor and opened a backdoor in the same. This backdoor called HANGMAN was able to steal the documents and upload them to a C&C server. The HANGMAN backdoor is finely crafted as it used SSL to encrypt the communications it made with C&C server.
FireEye researchers said: “The backdoor also wraps its communication protocol with SSL. HANGMAN begins communications by sending a legitimate SSL handshake to its command and control (C2) server. It then continues to communicate using SSL header messages, but the payload of the message is a custom binary protocol.”
However, the firm didn’t directly confirm the involvement of North Korea. It attributed the hack to North Korea as the backdoor made use of an IP address earlier spotted in another backdoor called MACKTRUCK. Also, the HANGMAN code was similar as seen in PEACHPIT and MACKTRUCK backdoors. It should be noted that these older backdoors were linked to North Korean government.
FireEye writes: “Both PEACHPIT and HANGMAN incorporate a function where Windows commands are passed to the backdoor from the remote C2 server. ”

Did you like this story? Tell your views in comments below.
spatsariya

Recent Posts

ByteDance Nears $50B Profit Despite TikTok’s U.S. Uncertainty

The future of TikTok is a topic of heated debate among lawmakers, while users fight…

1 hour ago

Meta Prepares Major AI Push With New Image, Video, and Text Models in 2026

When a company starts assigning fruits as codenames for AI models, it is an indicator…

1 hour ago

Bernstein Says Nvidia Stock Is a Buy After Valuation Reset

Purchasing Nvidia at this time may be similar to requesting a dessert after a massive…

4 hours ago

YouTube Suffers Global Outage, Services Quickly Restored

For a tiny fraction of time on Friday, the entire world simultaneously hit the refresh…

4 hours ago

Coatue Trims Nvidia, Boosts Alphabet Stock in Strategic AI Shift

The highly influential manager of Coatue Management, Philippe Laffont also made a bold asset reallocation…

5 hours ago

TikTok Finalizes US Spinoff Deal to Avoid Nationwide Ban

Tik Tok has signed a significant deal to sell its vast business units in the…

7 hours ago