Executive Summary
DOGCALL is a Windows backdoor employed by APT37 that infiltrates systems via exploit in the Hangul Word Processor. It grants remote control over infected machines, enabling data exfiltration and further attacks against South Korean government and military targets.
Enhanced Description
DOGCALL is a stealthy Windows backdoor that was attributed by analysts to APT37, the North Korean advanced persistent threat group known for targeting South Korean government and military entities. The malware entered victims’ systems in 2017 through an exploitation chain that began with a flaw in the Hangul Word Processor (HWP), the native word‑processing application used widely in Korea. Researchers have identified the HWP exploit as the initial dropper that downloads or directly installs DOGCALL onto a compromised machine. Once installed, DOGCALL provides attackers with persistent remote control capabilities over the infected host. The backdoor communicates with an external command and control (C2) infrastructure using encrypted channels, allowing APT37 actors to issue various commands ranging from data exfiltration to lateral movement instructions. While detailed post‑infection behaviors are sparse in public reports, typical characteristics of backdoors in this family include credential harvesting, keylogging, and the ability to spawn additional malicious modules. The impact on targeted organizations has been significant, compromising privileged accounts, leaking sensitive operational documents, and providing adversaries with footholds for follow‑up intrusion attempts. The use of an innocuous office application as a delivery vector underscores the importance of patching third‑party software and monitoring unusual document activity on enterprise networks.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information available on DOGCALL is limited mainly to its initial dropper via an HWP exploit and association with APT37. Detailed technical behavior, persistence methods, and full capabilities are not publicly disclosed, leading to a moderate confidence level in the provided analysis. Further investigation would require access to malware samples or additional analyst reports.
DOGCALL is a backdoor used by APT37 that has been used to target South Korean government and military organizations in 2017. It is typically dropped using a Hangul Word Processor (HWP) exploit. (Citation: FireEye APT37 Feb 2018)