Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

North Korean hackers launch newly detected cyberattack scheme

A new cyberattack campaign linked to North Korea has been detected using malicious code hidden in computer files, according to a report by the Genians Security Center, a South Korean cybersecurity institute.

The report identified the operation, called “Artemis,” as likely conducted by APT37, a hacking group believed to be backed by Pyongyang.

Attackers embedded harmful code using object linking and embedding (OLE) within Hangul Word Processor (HWP) documents, which are widely used in South Korea.

The attack is triggered when users enable document content and click on a hyperlink inside the file.

This method follows a pattern highlighted in an October report by 38 North, a US-based North Korea monitoring group, which noted repeated exploitation of the HWP format to target South Korean government, military, and industrial networks.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Hangul Word Processor (HWP)’s dominance in South Korea creates persistent attack surface

  • Hancom Office (the local office suite that includes HWP) holds about 30% share in South Korea, and government agencies often post files in proprietary formats 1.
  • The broad use creates a big target that North Korea-linked groups such as APT37 (Advanced Persistent Threat 37) hit often 2.
  • Limited use outside Korea and poor interoperability with Microsoft Office make HWP files hard to handle for teams, even as cross-border data-sharing grows 1.
  • APT37 has refined spear-phishing (targeted phishing) and fileless tactics 2. In March 2025 the group hid malicious LNK files (Windows shortcut files) in compressed archives with an HWP decoy. The payload deployed fileless RoKRAT malware (a remote access trojan that runs largely in memory to evade disk-based detection) to dodge signature-based antivirus 2.

Security vendors should build HWP-aware defenses for Korea

  • Persistent HWP abuse creates demand for specialized controls among Korean enterprises and government contractors. Buyers want content disarm and reconstruction (CDR), secure document viewers, plus email sandboxing as well as behavioral endpoint detection.
  • Genians reports a 78% share in Korea’s public and financial EDR (Endpoint Detection and Response) deployments 3.
  • New entrants should measure Hancom’s reach across target segments to estimate market size. Hancom also offers SDK (Software Development Kit) integration for document automation 4.
  • International vendors need detection and parsing for Hancom Office formats, including HWP, to compete. UK-South Korea data-sharing frameworks boost cross-border document flows that require security that works with any format 1.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.