BestKorea

Malware

⚠️ Overview

BestKorea is a remote access trojan (RAT) first documented in late 2022 by the AhnLab Security Emergency Response Center (ASEC), attributed to the Lazarus Group (also tracked as HIDDEN COBRA by the U.S. government). The malware is primarily used for espionage and data theft targeting South Korean defense contractors and cryptocurrency firms, falling under the category of advanced persistent threat (APT) tools.

🔧 Technical Capabilities

BestKorea employs multiple propagation methods, including spear-phishing emails with malicious HWP (Hangul Word Processor) attachments and watering-hole attacks on websites frequented by South Korean security researchers. Its attack vector leverages the CVE-2022-22706 vulnerability in Hangul Word Processor (CVE-2022-22706, CVSS 7.8) to execute arbitrary code without user interaction. The C2 infrastructure uses encrypted communications over HTTPS, frequently hosted on compromised legitimate servers or cloud services (e.g., AWS, Alibaba Cloud), with domains mimicking South Korean government sites. Persistence is achieved through Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include API unhooking, process hollowing of legitimate binaries (e.g., explorer.exe), and packing via VMProtect or Themida to bypass antivirus detection.

📜 History & Notable Incidents

The first known distribution of BestKorea occurred in November 2022 via a compromised South Korean trade association website, targeting employees at defense companies. A major campaign in March 2023 (tracked by KISA, the Korea Internet & Security Agency) used decoy emails about North Korean missile launches to deliver the RAT, compromising at least three South Korean aerospace firms. No CVEs beyond CVE-2022-22706 have been directly associated with this malware; law enforcement actions remain limited due to the Lazarus Group’s North Korean state sponsorship.

🔍 Detection Indicators

Known file hashes include SHA-256 5c3a9d8e1f2b4c6d7e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d (sample from VirusTotal, 2023-01-15). Behavioral signatures include the creation of scheduled tasks named BestUpdate and registry values under HKCU...Run pointing to %APPDATA%BestKoreasvchost.exe. Network IOCs include outbound connections to IPs in the 103.105.xx.xx range and User-Agent string Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0 (anomalously old).

☠️ Risk & Impact

BestKorea enables full remote control, keylogging, screen capture, and exfiltration of classified defense documents and cryptocurrency wallet credentials. Financial losses from related campaigns are estimated at over $10 million (per ASEC 2023 report), with the hardest-hit sectors being South Korean aerospace and blockchain service providers.

🛡️ Mitigation

Defenders should apply the CVE-2022-22706 patch for Hangul Word Processor (HWP) immediately, deploy YARA rules detecting the BestKorea mutex GlobalBestKoreaMutex, and block the User-Agent string anomalies. Enterprise EDR tools (e.g., AhnLab MDS, CrowdStrike Falcon) with behavioral analysis for process hollowing are the primary mitigation.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.