Talos has discovered a new malicious Hangul Word Processor (HWP) document targeting Korean users. If a malicious document is opened, a remote access trojan that we’re calling “NavRAT” is downloaded. NavRAT is a classic RAT that can download, upload, execute commands on the victim host and, finally, perform keylogging. It uses the legitimate Naver email platform in order to communicate with the attackers via email. An Encapsulated PostScript (EPS) object is embedded within the document. This object is used to execute malicious shellcode on the system.”]
Source: https://blog.talosintelligence.com/2018/05/navrat.html

