The attack campaign utilizes carefully crafted social engineering lures with document names such as “250615_Operation status of grain store.hwp” and “[Notice] Q1 VAT Return Filing Deadline (Final)” to entice victims into opening malicious attachments. The attack chain concludes with victims clicking a hyperlink labeled “[Appendix] Reference Materials.docx” at the document’s bottom, triggering a security warning that prompts execution of the embedded malware components. When victims access the document page containing these objects, the Hangul process automatically creates malicious files including ShellRunas.exe and credui.dll in the system’s temporary directory (%TEMP% path). This technique allows threat actors to execute malicious code while appearing to use trusted system components, significantly complicating detection efforts and enabling the deployment of RokRAT’s comprehensive data collection capabilities. Cybersecurity researchers have uncovered a sophisticated malware campaign where threat actors are exploiting Hangul Word Processor (.hwp) documents to distribute the notorious RokRAT malware. These documents contain seemingly legitimate content about North Korean grain distribution points, effectively masking their malicious intent while building credibility with targeted users. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. This marks a significant shift from the malware’s traditional distribution method through malicious shortcut (LNK) files, demonstrating the evolving tactics of advanced persistent threat groups. The primary attack vector utilizes ShellRunas.exe, a legitimate Windows utility, which automatically loads the malicious credui.dll from the same directory path. ASEC analysts identified that the malware leverages a sophisticated technique involving embedded OLE (Object Linking and Embedding) objects within the HWP documents. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Tushar is a Cyber security content editor with a passion for creating captivating and informative content.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 24 Jul 2025 14:50:37 +0000