Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 2017 campaign used malicious Hangul Word Processor (HWP) attachments to abuse how older HWP versions handled embedded PostScript/EPS content. The reported technique could place files or shortcuts in Windows startup locations; it was described as feature abuse, not a software exploit. Later HWP/EPS attacks did exploit specific vulnerabilities, so they should not be treated as the same incident or method.

How the 2017 HWP and PostScript technique worked

SecurityWeek reported on September 15, 2017, that malicious email attachments contained HWP documents with PostScript/EPS content. According to that account, older HWP versions did not properly restrict what embedded EPS content could do. The PostScript could manipulate files and place shortcuts or malicious files in startup folders, allowing activity to continue when Windows started. The report characterized this as abuse of a PostScript feature rather than exploitation of a software vulnerability. SecurityWeek’s 2017 account attributed the underlying research to Trend Micro.

Reported startup mechanisms

The 2017 report described variants that used different files and launch methods:

  • One placed a shortcut in a startup folder that invoked mshta.exe with JavaScript.
  • Another placed a DLL in %Temp% and used a shortcut to run it through rundll32.exe.

These details describe the variants covered by that report; they are not a universal behavior of HWP documents or all malware delivered through EPS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How later HWP/EPS attacks differed

Subsequent incidents included actual exploitation of vulnerabilities in EPS-related components. The CVE identifier, delivery chain, and malware differed across reports, so the cases should be compared individually rather than collapsed into one campaign.

Reported case HWP/EPS method Reported outcome
ROKRAT cases described by Microsoft and Morphisec Embedded EPS exploited the buffer-overflow vulnerability CVE-2013-0808. Microsoft says the EPS downloaded a binary. Morphisec reported a binary disguised as a JPG in its analyzed campaign.
RedEyes (also known as APT37 or ScarCruft), reported by ASEC in 2023 An HWP EPS vulnerability identified as CVE-2017-8291. ASEC said it did not recover the original HWP document, but obtained the EPS file that triggered the vulnerability. Shellcode retrieved a JPEG containing an encoded PE, wrote it under %temp%, and executed it.
RokRAT delivery case reported by AhnLab in 2025 AhnLab observed HWP documents being used for delivery rather than the LNK format it says RokRAT typically used. The report establishes an observed HWP delivery case, not widespread use of that format.

Sources: Microsoft’s ROKRAT threat entry, Morphisec’s Q1 2018 report, ASEC’s February 14, 2023 report, and AhnLab’s July 21, 2025 report.

What the malware could do

Impact depended on the payload. The 2017 account focused on placing files and startup shortcuts. Microsoft describes ROKRAT as a remote access trojan; Morphisec’s analysis says its sample could terminate processes, download and execute malware, log keystrokes, capture screenshots, and exfiltrate data. In a separate 2023 report, ASEC described M2RAT capabilities including remote control, keylogging, screenshots, and theft of files or recordings. These are sample-specific findings, not capabilities established for every HWP/PostScript attachment.

What changed in APT37’s delivery methods

Check Point Research reported that APT37 relied less on malicious documents after 2022 and increasingly hid payloads in oversized LNK files. It also noted evidence of malicious-document use as recently as April 2023. AhnLab’s 2025 report documents another HWP-based RokRAT delivery case. Together, these reports show that observed delivery methods changed over time, but do not establish that document-based delivery ended or that HWP was widely used in 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: Check Point Research’s 2023 analysis and AhnLab’s 2025 report.

How to reduce the risk

  • Install currently supported HWP releases and follow Hancom’s current security advisories. The 2017 report said versions from 2014 onward were not susceptible to the feature-abuse technique it described; that is historical guidance, not a current version or patch-status guarantee.
  • ASEC said in February 2023 that CVE-2017-8291 had been patched in the latest HWP version at that time and that Hancom had removed the third-party EPS module because of malicious EPS exploitation. This does not verify the status of current releases.
  • Keep Windows and antivirus or endpoint-protection products current, and be cautious with unexpected attachments, particularly those from unknown senders. Microsoft gives this general advice in its ROKRAT threat entry.

For incident response, an unexpected HWP attachment associated with suspicious startup shortcuts, mshta.exe, or rundll32.exe warrants investigation. Those indicators match variants in the 2017 report, but their presence alone does not prove that a particular file is malicious.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why these incidents should not be conflated

The 2017 report described abuse of older HWP EPS handling without an actual exploit. Other cases identify vulnerability exploitation: CVE-2013-0808 in the ROKRAT analyses and CVE-2017-8291 in ASEC’s 2023 RedEyes report. The sources do not establish that every case involved the same vulnerability, actor, delivery method, or payload. Morphisec described North Korea as its most likely suspect for its analyzed campaign while explicitly leaving the attack unattributed; that assessment is not confirmed attribution.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.