Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware DOGCALL

DOGCALL

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

DOGCALL is a Windows backdoor employed by APT37 that infiltrates systems via exploit in the Hangul Word Processor. It grants remote control over infected machines, enabling data exfiltration and further attacks against South Korean government and military targets.

Enhanced Description

DOGCALL is a stealthy Windows backdoor that was attributed by analysts to APT37, the North Korean advanced persistent threat group known for targeting South Korean government and military entities. The malware entered victims’ systems in 2017 through an exploitation chain that began with a flaw in the Hangul Word Processor (HWP), the native word‑processing application used widely in Korea. Researchers have identified the HWP exploit as the initial dropper that downloads or directly installs DOGCALL onto a compromised machine. Once installed, DOGCALL provides attackers with persistent remote control capabilities over the infected host. The backdoor communicates with an external command and control (C2) infrastructure using encrypted channels, allowing APT37 actors to issue various commands ranging from data exfiltration to lateral movement instructions. While detailed post‑infection behaviors are sparse in public reports, typical characteristics of backdoors in this family include credential harvesting, keylogging, and the ability to spawn additional malicious modules. The impact on targeted organizations has been significant, compromising privileged accounts, leaking sensitive operational documents, and providing adversaries with footholds for follow‑up intrusion attempts. The use of an innocuous office application as a delivery vector underscores the importance of patching third‑party software and monitoring unusual document activity on enterprise networks.

Key Capabilities

  • Remotely controllable backdoor
  • C2 communication with encrypted channels
  • Persistent foothold via startup mechanisms
  • Potential for credential harvesting
  • Data exfiltration capabilities

ATT&CK Techniques

T1059.003
T1105
T1070.004

Recommended Actions

  • Deploy endpoint detection and response (EDR) solutions tuned to detect DOGCALL signatures or anomalous process behavior
  • Implement strict least‑privilege policies for office applications, especially Hangul Word Processor
  • Patch or disable unpatched HWP versions immediately
  • Block outbound traffic to known C2 IP addresses associated with APT37
  • Conduct regular host integrity checks and monitor for unauthorized persistence mechanisms

Suggested Tags

APT37
DOGCALL
backdoor
Windows
Hangul Word Processor Exploit
KoreanGovernmentTargeting

Confidence Assessment

The information available on DOGCALL is limited mainly to its initial dropper via an HWP exploit and association with APT37. Detailed technical behavior, persistence methods, and full capabilities are not publicly disclosed, leading to a moderate confidence level in the provided analysis. Further investigation would require access to malware samples or additional analyst reports.

Description

DOGCALL is a backdoor used by APT37 that has been used to target South Korean government and military organizations in 2017. It is typically dropped using a Hangul Word Processor (HWP) exploit. (Citation: FireEye APT37 Feb 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.