Skip to content

Update file_extensions_suspicious.txt#469

Merged
aidenmitchell merged 1 commit intomasterfrom
Update-file_extensions_suspicious
Jun 20, 2025
Merged

Update file_extensions_suspicious.txt#469
aidenmitchell merged 1 commit intomasterfrom
Update-file_extensions_suspicious

Conversation

@brycampbell
Copy link
Copy Markdown
Member

@brycampbell brycampbell commented Jun 20, 2025

Both Google and Ahnsec report independently on the misuse of .hwp files. i previously suggesting adding it here as a suspicious extension, and

Ahn: https://asec.ahnlab.com/en/88465/
Mandiant: https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure-alignment-2023

The preferred method of delivery is via this file format by some of the DPRK groups responsible for espionage. The file types themselves often rely on OLE file content, so the risk of erroneous files is minimal but still poses a historic risk as per the intelligence reporting.

Hunt-1

@brycampbell brycampbell added the review-needed Indicates that a PR is waiting for review label Jun 20, 2025
@aidenmitchell aidenmitchell merged commit b63906d into master Jun 20, 2025
3 checks passed
@aidenmitchell aidenmitchell deleted the Update-file_extensions_suspicious branch June 20, 2025 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants