HAPPYWORK

HAPPYWORK is a downloader used by APT37 to target South Korean government and financial victims in November 2016. [1]

ID: S0214
Type: MALWARE
Platforms: Windows

Version: 1.0

Techniques Used

DomainIDNameUse
EnterpriseT1105Remote File Copycan download and execute a second-stage payload.[1]
EnterpriseT1082System Information Discoverycan collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.[1]
EnterpriseT1033System Owner/User Discoverycan collect the victim user name.[1]

Groups

Groups that use this software:

APT37

References