logo

CHM Malware Stealing User Information Being Distributed in Korea

ID: 707066b4-9b4b-52d9-8096-d379d5bcb3f6

STIX ID: report--707066b4-9b4b-52d9-8096-d379d5bcb3f6

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-05-08

Date Updated: 2026-04-26

Author: gygy0101

...
...

AhnLab ASEC identified a CHM-based malware campaign targeting Korean users that uses a multi-stage chain (CHM -> Link.ini -> bootservice.php -> OfficeUpdater service -> loggerservice.php) and fileless techniques to deliver obfuscated PowerShell payloads. The malware collects system and file listings, running process details and anti-malware information, performs keylogging and clipboard capture, persists by registering a service that runs periodically, and exfiltrates data to the attacker; detection is reported as Dropper/CHM.Generic with MD5 b2c74dbf20824477c3e139b48833041b.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.