HWP Malware Using the Steganography Technique: RedEyes (ScarCruft)

HWP Malware Using the Steganography Technique: RedEyes (ScarCruft)

In January, the ASEC (AhnLab Security Emergency response Center) analysis team discovered that the RedEyes threat group (also known as APT37, ScarCruft) had been distributing malware by exploiting the HWP EPS (Encapsulated PostScript) vulnerability (CVE-2017-8291). This report will share the RedEyes group’s latest activity in Korea. 1. Overview The RedEyes