logo

Malicious HWP Document Disguised as Reunification Education Support Application

ID: 2fb79d32-287f-5efe-beaf-18f11812cc34

STIX ID: report--2fb79d32-287f-5efe-beaf-18f11812cc34

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-03-12

Date Updated: 2026-04-26

Author: ATCP

...
...

The AhnLab ASEC report details a malicious HWP document distributed via a public recruitment post that, when opened, extracts a normal HWP plus malicious files (BAT, EXE, manifest, XML), creates files in the TEMP folder, registers Task Scheduler entries for persistence, and downloads/executes additional payloads from an external URL; multiple MD5 hashes and the URL are provided as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.