BestKorea is a remote access trojan (RAT) first documented in late 2022 by the AhnLab Security Emergency Response Center (ASEC), attributed to the Lazarus Group (also tracked as HIDDEN COBRA by the U.S. government). The malware is primarily used for espionage and data theft targeting South Korean defense contractors and cryptocurrency firms, falling under the category of advanced persistent threat (APT) tools.
BestKorea employs multiple propagation methods, including spear-phishing emails with malicious HWP (Hangul Word Processor) attachments and watering-hole attacks on websites frequented by South Korean security researchers. Its attack vector leverages the CVE-2022-22706 vulnerability in Hangul Word Processor (CVE-2022-22706, CVSS 7.8) to execute arbitrary code without user interaction. The C2 infrastructure uses encrypted communications over HTTPS, frequently hosted on compromised legitimate servers or cloud services (e.g., AWS, Alibaba Cloud), with domains mimicking South Korean government sites. Persistence is achieved through Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include API unhooking, process hollowing of legitimate binaries (e.g., explorer.exe), and packing via VMProtect or Themida to bypass antivirus detection.
The first known distribution of BestKorea occurred in November 2022 via a compromised South Korean trade association website, targeting employees at defense companies. A major campaign in March 2023 (tracked by KISA, the Korea Internet & Security Agency) used decoy emails about North Korean missile launches to deliver the RAT, compromising at least three South Korean aerospace firms. No CVEs beyond CVE-2022-22706 have been directly associated with this malware; law enforcement actions remain limited due to the Lazarus Group’s North Korean state sponsorship.
Known file hashes include SHA-256 5c3a9d8e1f2b4c6d7e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d (sample from VirusTotal, 2023-01-15). Behavioral signatures include the creation of scheduled tasks named BestUpdate and registry values under HKCU...Run pointing to %APPDATA%BestKoreasvchost.exe. Network IOCs include outbound connections to IPs in the 103.105.xx.xx range and User-Agent string Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0 (anomalously old).
BestKorea enables full remote control, keylogging, screen capture, and exfiltration of classified defense documents and cryptocurrency wallet credentials. Financial losses from related campaigns are estimated at over $10 million (per ASEC 2023 report), with the hardest-hit sectors being South Korean aerospace and blockchain service providers.
Defenders should apply the CVE-2022-22706 patch for Hangul Word Processor (HWP) immediately, deploy YARA rules detecting the BestKorea mutex GlobalBestKoreaMutex, and block the User-Agent string anomalies. Enterprise EDR tools (e.g., AhnLab MDS, CrowdStrike Falcon) with behavioral analysis for process hollowing are the primary mitigation.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.