HMView

Bot User-Agent: hmview

⚠️ Overview

HMView, also known as HM RAT or Hackersome Management View, is a sophisticated remote access trojan first documented in 2015 by the South Korean cybersecurity firm AhnLab. Analysis by Kaspersky and the Korea Internet & Security Agency (KISA) attributes its development to North Korean threat actors, specifically subgroups of the Lazarus Group (e.g., BlueNoroff). The tool is primarily used for targeted espionage against government entities, defense contractors, and cryptocurrency exchanges in South Korea. HMView is often delivered via spear-phishing emails containing malicious Microsoft Office documents or HWP (Hangul Word Processor) files. Its source code is not publicly available, but multiple variants have been reverse-engineered and documented in threat intelligence reports.

🔧 Technical Capabilities

HMView functions as a modular RAT with extensive reconnaissance and data theft capabilities. It can capture full-screen screenshots, record keystrokes (including passwords and crypto wallet credentials), exfiltrate clipboard content, enumerate running processes, and upload/download arbitrary files to and from the victim. The trojan also supports audio recording via built-in microphones and can log active window titles to track user behavior. Communication with command-and-control (C2) servers is performed over HTTP or HTTPS POST requests; the C2 payload is encrypted using a custom XOR cipher with a hardcoded key, then Base64‑encoded. HMView periodically beacons to its C2 and can receive commands to uninstall itself, update its configuration, or execute shell commands. The malware is typically injected into legitimate processes like explorer.exe or svchost.exe using process hollowing, making it difficult to detect with traditional signature-based antivirus solutions.

📜 History & Notable Incidents

HMView gained notoriety during Operation Cloudburst (2016), a cyber‑espionage campaign targeting South Korean defense contractors and military personnel. In 2018, a variant of HMView was used in attacks against South Korean cryptocurrency exchanges, stealing over $30 million in digital assets as reported by FireEye. The malware has been linked to multiple CVEs, including CVE-2017-0199 (Microsoft Office remote code execution) and CVE-2018-20250 (WinRAR ACE extraction vulnerability), both employed as initial infection vectors in HMView campaigns. AhnLab’s annual threat reports from 2019–2021 consistently list HMView among the top 10 malware families targeting South Korea, with hundreds of new samples discovered each year.

🔍 Detection Indicators

While HMView does not have a fixed User‑Agent string, its HTTP requests often include distinctive headers such as “User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko” and a custom field “X-Requested-With: XMLHttpRequest”. Network traffic analysis reveals periodic beaconing to domains mimicking legitimate services (e.g., microsoft-update[.]com, google-analytics[.]org). File‑based indicators include a mutex name pattern like “HMV_%d” and dropped DLLs with the export function “ServiceMain” that act as persistence mechanisms via scheduled tasks. Memory forensic investigators can find injected code segments starting with the XOR decryption stub 0xE8 0x?? 0x?? 0x?? 0x?? 0x83 0xC4.

☠️ Risk & Impact

HMView poses a critical threat to targeted organizations, enabling complete remote control over infected hosts. Attackers can exfiltrate classified documents, intellectual property, login credentials, and cryptocurrency private keys, often leading to significant financial loss and national security breaches. The malware’s ability to record audio and video also allows for blackmail and long‑term surveillance. In high‑value targets, HMView infections have resulted in the theft of military blueprints and diplomatic communications, as documented in KISA breach reports.

🛡️ Mitigation

Upon detection, HMView is immediately blocked—all network traffic matching known beaconing patterns or C2 domain signatures is dropped at the perimeter firewall, and any associated file hashes are quarantined by endpoint protection systems. Because HMView is a confirmed malicious bot used by state‑sponsored actors, any observed infection triggers an incident response escalation to prevent lateral movement and data exfiltration.

53% of Web Traffic Is Bots in 2026

— Imperva Bad Bot Report 2026

How much of your traffic is automated? Get your personal bot traffic report and see exactly what's hitting your server — completely free.

📊 Get My Bot Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.