• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Thursday, June 11, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home News

Internet Explorer falls prey to North Korean Hackers yet again

by Sneha Singh
December 10, 2022 - Updated On December 13, 2022
in News
Reading Time: 2 mins read
0
TAG
TwitterWhatsappLinkedin

There are still a few things that Internet Explorer cannot do that Microsoft’s Edge browser can. Unfortunately, a North Korean-backed organization allegedly exploited one of them this autumn, located deep inside Microsoft Word. According to Google’s Threat Analysis Group (TAG), the government-backed APT37 has previously taken advantage of Internet Explorer’s lingering presence.

You might also like

Opendoor’s India Exit Impacts 250 Employees as Company Restructures Globally

Salesforce Cuts Jobs, Offers Generous Severance Package

Corporate Divergence Sam Altman’s Eyeball-Scanning Startup Downsizes as OpenAI Files for Historic IPO

APT37 has targeted South Korean journalists, activists, and North Korean defectors with resounding success using a limited but nonetheless practical Internet Explorer approach.

Visitors to Daily NK, a South Korean website devoted to North Korean news, were the focus of the most recent operation. This one involves the Itaewon Halloween crowd crush, which resulted in at least 151 fatalities. A Microsoft Word.docx document with the subject line “accident reaction issue” began to go around. It appeared to be timed and dated less than two days after the occurrence.

Users in South Korea started uploading the document to the Google-owned VirusTotal. It was marked with the long-known Word and WordPad vulnerability, CVE-2017-0199.
Similar to April 2017, if you choose to read the document in Word/WordPad outside of the “Protected View.”

TAG

TAG is a better way to understand the stratergies

The paper will download HTML that resembles Rich Text Format templates and a rich text template from an attacker-controlled site. In what Microsoft refers to as “specially crafted files,” Office and WordPad inherently use Internet Explorer. It displays HTML, providing an entry point for attackers to upload different malware payloads. The vulnerability was fixed that same month, but it continued to exist; more than a year later, a Petya wave used it as one of its vectors.

The JavaScript engine in Internet Explorer is the source of the specific vulnerability. Memory writing and data type confusion result from a mistake. Those mistakes were made during just-in-time optimization. Additionally, this particular vulnerability cleaned up by erasing its existence from the Internet Explorer cache and history. Google’s TAG is unaware of the payloads that were sent.

But APT37 has previously spread vulnerabilities that activated BLUELIGHT, ROKRAT, and DOLPHIN, all of which centered on the political and economic objectives of North Korea.
Even though Microsoft fixed the exact weakness in its JScript engine, remote-code Word doc assaults appear to be here to stay, given that this is their sixth year. And performers in North Korea will be delighted to portray them.

TAG is dedicated to disseminating research to educate the security community about bad actors like APT37. Additionally, to increase safeguards throughout the ecosystem, TAG better understands the strategies and methods used by these kinds of actors.

Tags: APT37North KoreatagWordWordPad Vulnerability
Tweet54SendShare15
Previous Post

Former FTX CEO may face subpoena after ignoring US Senate’s request

Next Post

Next Gen Virtual Reality Has Arrived

Sneha Singh

Sneha is a skilled writer with a passion for uncovering the latest stories and breaking news. She has written for a variety of publications, covering topics ranging from politics and business to entertainment and sports.

Recommended For You

Opendoor’s India Exit Impacts 250 Employees as Company Restructures Globally

by Rounak Majumdar
June 11, 2026
0
Opendoor's India Exit Impacts 250 Employees as Company Restructures Globally

US-based real estate technology company Opendoor has decided to shut down its India operations, resulting in the layoff of around 250 employees. The move is part of a...

Read more

Salesforce Cuts Jobs, Offers Generous Severance Package

by Afeefa Ansari
June 11, 2026
0
Salesforce

Salesforce, one of the world’s largest cloud software companies, has just announced another round of job cuts as it continues to reshape its workforce around artificial intelligence and...

Read more

Corporate Divergence Sam Altman’s Eyeball-Scanning Startup Downsizes as OpenAI Files for Historic IPO

by Anochie Esther
June 11, 2026
0
Sam Altmans eye scanning startup layoff

A striking tale of two corporate trajectories is playing out across the tech sector. While generative artificial intelligence continues to attract historic waves of investment, other foundational tech...

Read more
Next Post
[Image: Pexels / Harsch Shivam]

Next Gen Virtual Reality Has Arrived

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?