HAPPYWORK

S0214

Malware.View on attack.mitre.org

About this malware

HAPPYWORK is a downloader used by APT37 to target South Korean government and financial victims in November 2016.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1033
System Owner/User Discovery

can collect the victim user name.

T1082
System Information Discovery

can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.

T1105
Ingress Tool Transfer

can download and execute a second-stage payload.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.