
HanCom Solutionware. The code that became Korea's national word processor lasted thirty years. North Korea spent those years probing the seams.
Dennis Kim former Cyworld CEO / 10 October 2026
Classification: TLP:CLEAR | Type: Analytical Column | Date: 2026-10-10 Severity: HIGH | Confidence: A2 | Actors: APT37 · Kimsuky
Code does not age. The people who understand it do. A domestic word processor that became Korea's document infrastructure — and the unfinished work left by thirty-year-old code.
Master version (9 October 2026)
Opening — This month, HWP is blocked on civil-servant mail
If the government plan holds, October 2026 is when HWP attachments are restricted on the public-official integrated mailbox that civil servants use with citizens. Local-government Onnara systems already expanded HWPX mandates from 18 May. The official reason is "documents AI can read." There is another reason that barely appears in press releases. For more than a decade, HWP has been the most reliable door for North Korean hacking.
In December 2025, Genians Security Center published APT37's Operation Artemis. Operators posed as university professors or broadcast writers, built trust over several conversations, then sent HWP files dressed as interview questionnaires or event notices. Infection started when the victim opened the document, allowed content to run, and clicked a "hyperlink" in the body. That link was an OLE object painted to look like a link.
38 North, in an October 2025 report, diagnosed the fact itself — that HWP is the de facto standard across Korean ministries, the military, core industry, and academia — as a cyber-security weakness for South Korea and the U.S.–ROK alliance.
Why Hangul, of all software? This column answers in three layers — history, culture, technology — and then the problem almost no one discusses in earnest: thirty-year-old C code, and the aging of the people who still understand it.
1. A word processor born for Korean
Hangul Word Processor was started in 1988 by Lee Chan-jin, Kim Hyung-jip, Woo Won-sik, Kim Taek-jin and others from a Seoul National University computing club, and shipped as version 1.0 in 1989. The product name ᄒᆞᆫ글 keeps the obsolete vowel arae-a (ㆍ). Hangul and Computer (Hancom) was founded in 1990 and commercialized the product in earnest.
Foreign word processors of the time could not handle Korean properly. A Hangul syllable is an onset–nucleus–coda cluster; modern Hangul alone has 11,172 syllables. Hangul Word Processor met that problem head-on with johap-hyeong (combining) codes, then added mixed Hangul–Hanja, vertical writing, and Korean paragraph and tracking control, and became the "people's word processor."
Korean is an agglutinative language of particles and endings, mixing Sino-Korean with native words; official and academic documents are thick with mixed-script Hanja and special symbols. Hangul answered that typesetting demand first and most accurately. Microsoft Word knocked on the Korean market in the mid-1990s and did not clear the wall of Korean layout quality and user habit. The "Defend Hangul" campaign against Microsoft's investment offer during the 1998 financial crisis showed that this software was more than a product in Korean society.
That same symbolism later became an opportunity for attackers.
2. A country of tables — and why the format became "Korea-only"
The table culture of official documents
Korean administrative documents are defined by tables and gaejosik (itemized bureaucratic prose). Drafts, reports, plans, budgets, even one-page situation notes mostly split items into cells and fill them with sentences ending in "함" or "임." Cell merges, border weights, line spacing, fonts and compression ratios are prescribed; a slight miss earns "do it again" — a long-standing landscape of public service.
Hangul was overwhelming at this table editing. Drawing complex tables, splitting and merging cells, even calculating inside a table became the work method of civil servants and researchers itself.
Why only Korea uses HWP — political-economic lock-in
Features are not enough. HWP's dominance has been held by several layers of lock-in, along with national sentiment.
- System lock-in. The government work-management system Onnara used HWP as the default document format. Because civil servants used HWP, vendors, research institutes, and schools had to submit in HWP.
- Template-asset lock-in. Decades of official forms, grant applications, and bid templates are all HWP. Changing the format means remaking tens of thousands of forms.
- Procurement and industrial policy. Under the banner of nurturing domestic software, Hancom Office was long the default in public procurement.
- Symbolic lock-in. The narrative of "domestic software standing up to foreign products" made conversion emotionally harder.
From an attacker's view this structure is decisive. A file format the target opens every day, a format nobody distrusts when opening, and a format that in practice only Korea uses. Those three conditions meet at HWP. Microsoft Word and PDF are watched by the global security industry; HWP is watched, in practice, only by Korean security. Attacks collect where fewer eyes are looking.
"G7 summit — BH policy changes"
If a document with that title arrived as HWP by mail or KakaoTalk, almost no bureaucrat would refuse to click.
3. The character of the defects — two attack axes
Attacks on HWP split into two branches of completely different character. Mix them up and the prescription points at the wrong place.
First — memory defects: the document is owned the moment it is "read"
The legacy HWP 5.0 format stacks proprietary binary records, compressed, on Microsoft's OLE Compound File. Hancom has published format specs, but more than thirty years of backward-compatibility demands leave the parser with an enormous number of exceptions and branches. A complex binary parser is a wide attack surface.
Public vulnerabilities show a clear pattern.
| Period | Identifier | Type | Notes |
|---|---|---|---|
| 2015 | CVE-2015-6585 | Type confusion | FireEye confirmed as a North Korea–linked zero-day; Hancom patched 7 September |
| 2016–2020 | CVE-2017-8291 and others | Embedded Ghostscript (EPS) bugs | An external C library that rendered EPS pictures inside HWP became a path |
| 2022 | CVE-2022-33896 | Buffer underflow | Memory defect in XML-based document parsing |
| Published 2026.02 | CVE-2025-29867 | Type confusion (CWE-843) | Hancom Office 2018·2020·2022·2024 entire line, CVSS 4.0 8.5. No confirmed in-the-wild abuse at disclosure |
Type confusion, buffer overflow/underflow, and use-after-free are all defects typical of memory-unsafe languages such as C/C++. Patch one and a cousin appears elsewhere. This is not one developer's mistake; it is a language and architecture problem. Ghostscript shows the problem is not only in Hancom's own code. An external C library pulled in to draw a picture inside a document can be an attack point too.
Second — abuse of a normal feature: no bug required
HWP can embed OLE objects. The original purpose is tables, pictures, and data from other programs. In Operation Artemis the operators disguised an OLE object as an ordinary hyperlink. Even if the software has zero bugs, infection completes when the user ignores a warning and clicks once. Dropping a shortcut (.lnk) with an HWP icon inside an archive is the same family.
The core of this axis is not technology but trust. Operators impersonate professors, reporters, broadcast writers, or research-institute staff and talk for weeks before sending a file.
The two axes demand different prescriptions
| Axis A: memory defects | Axis B: abuse of normal features | |
|---|---|---|
| Moment of attack | The instant the document is opened (parsed) | The instant the user allows / clicks |
| Representative cases | CVE-2015-6585, EPS/Ghostscript | Operation Artemis, HWP+LNK |
| Stopped by a patch? | Individual bugs yes; the family repeats | No (the feature itself is normal) |
| Root prescription | Memory-safe language migration, sandbox | CDR / document inspection, user behavior |
An HWP rewritten in Rust still falls if the user clicks a disguised link. Conversely, no amount of training stops a zero-day that executes on open. Either one alone is not enough.
4. Thirteen years of North Korean HWP targeting
| Period | Actor | Content | Axis |
|---|---|---|---|
| 2013 | Kimsuky | Kaspersky first published the Kimsuky campaign. Included a dedicated module to steal HWP documents. Before it was an intrusion tool, HWP was a collection target | Collection |
| 2015 | Suspected DPRK-linked | FireEye published HWP zero-day CVE-2015-6585 and the Hangman backdoor. C2 overlapped other suspected DPRK operations | A |
| 2016–2020 | Multiple DPRK-linked | Years of HWP lures with malicious EPS, disguised as unification/security seminar material or virtual-asset documents | A |
| 2017 | APT37 | HWP spearphishing against ~20 people in diplomacy, security, unification | A+B |
| 2023 | Kimsuky | Six U.S. and Korean agencies (FBI, State, NSA; NIS, National Police, MOFA) issued a joint advisory. Warned of social engineering posing as reporters and scholars | B |
| 2025.03 | APT37 | Operation ToyBox Story. LNK files disguised as HWP against North Korea–related activists | B |
| 2025.08–11 | APT37 | Operation Artemis. Professor/broadcast-writer impersonation, OLE hyperlink disguise, steganography plus DLL side-loading | B |
The chronology is clear. Through the mid-2010s Axis A (vulnerabilities) was the main effort. As Hancom patched faster and embedded Ghostscript was removed, weight moved to Axis B (social engineering and trusted-feature abuse). The 2023 U.S.–ROK joint advisory stressed that Kimsuky does not attach malware to the first mail, and spends a long time building trust.
5. North Korea still hunts HWP
North Korean HWP attacks are not past tense. In 2026 the industry still reports variants that combine HWPX with script files (JSE), and Kimsuky chains that weave HWP with LNK.
One more point. Operators already use HWPX as bait. Switching to an open format does not end this war. They follow not the format but the work flow the target trusts. If Korean public agencies use HWPX, the lure becomes HWPX. If official mail is blocked, they move to messengers and cloud links.
6. What we should do
Prescriptions must be designed for both axes. This column proposes four. The first two address Axis A, the third Axis B, the fourth organizations and individuals.
First, move thirty-year-old C code to a memory-safe language [Axis A]
This is the part of the column I most want emphasized.
Hangul's roots are late-1980s DOS-era C. It expanded to C/C++ through the Windows era, and more than thirty years of features and compatibility code were layered on top. Direct pointers and hand-allocated memory were then the best choice for performance. Today that code is the point North Korea has been digging for more than a decade. At one time they even rendered without MFC, because GDI differed by Windows version.
Then the human problem. The first-generation developers of Hangul are now around sixty, and most left the company long ago. People who deeply understand the original design and internals shrink, while the code stacked on top keeps growing. Code does not age, but the people who understand it do. The greatest risk in a legacy system is this break in knowledge.
The world's direction is already set.
- Microsoft has said about 70% of the security vulnerabilities it patches in its own products each year are memory-safety issues.
- Google reported that after writing new Android code in Rust and other memory-safe languages, memory-safety bugs as a share of all vulnerabilities fell from 76% in 2019 to 24% in 2024. The core point: changing only new code, without rewriting all existing C/C++, already worked.
- CISA, NSA, FBI and allied cyber agencies jointly recommended in 2023 that software makers write a "memory-safe roadmap"; the White House ONCD officially urged a shift to memory-safe languages in 2024.
- DARPA is pushing TRACTOR, using AI to automatically convert C to Rust.
Moving millions of lines of C used to be unrealistic. There is now a new tool: LLM-based code migration. A realistic order:
- Move the parser first. Axis A attacks happen the moment a document is "read." Rewrite HWP/HWPX parsers and image/OLE modules — the boundary code that takes external input — in Rust.
- Convert with AI, verify with tests. An LLM does a first-pass C-to-Rust conversion; differential testing and fuzzing run millions of the same documents through old and new engines. Hancom has a thirty-year corpus of real documents no other company has. The LLM is a translator, not a judge. Tests judge.
- Cage remaining C. Isolate what cannot move yet in a sandbox so a breach does not become a system-wide fire.
- Leave knowledge as code. Documenting legacy behavior with LLMs during conversion, and pinning it with tests, preserves first-generation tacit knowledge in a form the next generation can read.
Who pays? Honestly, this work is large for Hancom alone. Firms do not spontaneously spend tens of billions of won on a security rewrite that does not grow revenue. But as long as HWP is national document infrastructure, this is not one company's quality problem; it is national cyber security. Two levers are needed.
- Procurement conditions. Require a memory-safe roadmap for document software public agencies buy — the same way the United States ties Secure by Design to procurement.
- Joint R&D. Support parser rewrite and fuzzing infrastructure as national R&D, and open-source part of the result (especially an HWPX parser) so the whole security industry can verify it.
Second, push the open-document transition all the way. Shrink the exposure of a single word processor.
The government mandated HWPX on central-ministry Onnara in 2022 and expanded it to local government from 18 May 2026. On-mail between officials and the citizen-facing official mailbox restrict HWP attachments from October. HWPX follows the XML open document standard (OWPML, KS X 6101); rename the extension to zip and the internals are readable as-is.
The real value of the switch is inspectability. Structure must be transparent for automated inspection, CDR, and AI analysis. As above, an open format is not a safe format. Parsing bugs have been reported in HWPX, and operators already use it. Format conversion is a starting line, not a finish.
Third, build an LLM-based document inspection stack
If the LLM in the first item is a tool that repairs code, the LLM here is a tool that inspects incoming documents. Same technology, different job.
Axis B is hard to catch with signatures. It is not malware; it is a normal feature plus a plausible context. So inspection that reads context is needed. After structurally extracting OLE objects, external links, scripts, and metadata from HWPX, an LLM can ask:
- "If this is an interview questionnaire, why is there an executable object inside?"
- "Does the link text in the body match the actual destination?"
- "Do the affiliation of the alleged professor-sender and the document's style and metadata match?"
Even here the LLM is not the final judge. A deterministic engine confirms risk elements; the LLM filters suspicion upstream and explains in language a human can understand. Moving decades of old HWP into HWPX or structured data is also a base for this inspection stack and for public-data use.
Fourth, organizations default to CDR; individuals keep five habits [org · individual]
Organizations. CDR (Content Disarm and Reconstruction) strips executable elements — OLE objects, scripts, external links — and rebuilds a safe document. It works whether a vulnerability is known or not, so it hits both Axis A zero-days and Axis B disguised links. Documents from outside should open only after CDR, as the mail-gateway default.
Individuals. Policy and technology take years to change. What North Korea is aiming at in the meantime is one person's click.
Five things you can do from today
- If a professor, reporter, or writer contacting you for the first time sends a document, confirm once through a channel you already know. The 2023 U.S.–ROK joint advisory recommended a short video call to confirm identity — even if that means a bare-face video call.
- If opening a document shows "Enable Content" or "Run," do not click. A normal report or questionnaire does not ask that permission.
- A link or icon inside a document is not the document. If you must, inspect the URL yourself and type it into a browser separately.
- Turn on "show file extensions" in Windows Explorer. A
.lnkwearing an HWP icon is not a document; it is an executable.- Keep Hancom Office current, and replace versions that are out of support. If you received a suspicious document, report it to KISA (118) or the National Intelligence Service (111).
7. Anticipated objections and replies
Then why not just switch to Microsoft Word?Word-adoption talk has even appeared among civilian members of the National AI Strategy Committee. Switching to Word does not remove a single attack axis; itmoves you onto another company's C++ parser. Word has long been a regular path for macro and OLE abuse. You also have to count the cost of throwing away decades of public templates and Korean typesetting assets, and the risk of parking national core document infrastructure on one foreign firm. The question is not "domestic or foreign" but inspectable and memory-safe? If that bar is met, HWPX, DOCX, or ODF will do. HWPX is the realistic starting point because it moves existing template assets with the least loss.
What about conversion costs for civil servants and researchers?They are not small. Old forms break, users on old versions cannot open files, and inter-ministry system links need work. That is why the government chose a staged approach: five months of grace on official mail, starting with notice pop-ups. Conversion costs are real, but the comparison changes againstthirteen years of intrusion costs.
Has Hancom done nothing?No. Hancom has supported HWPX since 2010 and made HWPX the default save format in a 2021 regular patch. Around 2018 it removed the embedded Ghostscript module that had become an attack path, and it issues patches through KrCERT/CC when vulnerabilities are reported. The point of this column is not that Hancom has not tried, but thatpatches and format conversion as they currently exist cannot end a defect family at the language level. The next step is changing the foundation of the code.
Does switching to Rust end North Korean hacking? No. As chapter 3 showed, Rust shrinks Axis A; it does not stop Axis B clicks on disguised links. That is why the four prescriptions are one bundle.
Closing
In 1989, when foreign software could not handle Hangul, a handful of university students changed how this country writes documents in Korean. The C they wrote has held up administration, research, and industry for more than thirty years.
That code still runs as it did then. What changed is the world outside. North Korea has been digging its seams for thirteen years, and the people who first designed it have been leaving the field one by one. This October, when HWP is blocked on civil-servant mail, must be a beginning, not an end. After the format, change the code. After the code, leave the knowledge for the next generation.
If 1989's students had C, 2026's we have AI and memory-safe languages. Rewriting Hangul is not throwing the inheritance away. It is making that inheritance last another thirty years.
References
North Korean HWP attack cases
- 38 North, "HWP as an Attack Surface: What Hancom's Hangul Word Processor Means for South Korea's Cyber Posture as a US Ally" (2025.10): https://www.38north.org/2025/10/hwp-as-an-attack-surface-what-hancoms-hangul-word-processor-means-for-south-koreas-cyber-posture-as-a-us-ally/
- Genians Security Center, Operation Artemis analysis (2025.12): https://www.genians.co.kr/en/blog/threat_intelligence/dll
- Genians Security Center, "Operation: ToyBox Story" (2025.05): https://www.genians.co.kr/blog/threat_intelligence/toybox-story
- Boan News, "APT37 'Artemis' caught after opening a Hangul file" (2025.12.22): https://m.boannews.com/html/detail.html?idx=141110
- Boan News, "APT37's meticulous spearphishing techniques" (2023.06.13): https://m.boannews.com/html/detail.html?idx=119028
- Chosun Biz, "HWP as bait — Hangul Word Processor as North Korean hackers' prey" (2025.12.26): https://biz.chosun.com/it-science/ict/2025/12/26/6BU7EWAVA5FVDADT3W4XPQI4BU/
- KBS, "Infection after opening a Hangul file — North Korean hacking 'Artemis' caught" (2025.12.22): https://newsws.kbs.co.kr/news/pc/view/view.do?ncd=8439673
- Korea JoongAng Daily, "Pyongyang-backed hackers launch newly detected cyberattack scheme using computer files" (2025.12): https://www.koreajoongangdaily.com/korea/pyongyang-backed-hackers-launch-newly-detected-cyberattack-scheme-using-computer-files/12026158
- Kaspersky Securelist, "The 'Kimsuky' Operation: A North Korean APT?" (2013.09): https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/
- SecurityWeek, "North Korea Suspected of Using Zero-Day to Attack South" (2015.09): https://www.securityweek.com/north-korea-suspected-using-zero-day-attack-south/
- Computerworld, "North Korea is likely behind attacks exploiting a Korean word processing program" (2015.09): https://www.computerworld.com/article/1632897/north-korea-is-likely-behind-attacks-exploiting-a-korean-word-processing-program.html
- Trend Micro, "HWP and PostScript Abused Via Malicious Attachments" (2017.09): https://www.trendmicro.com/en/research/17/i/hangul-word-processor-postscript-abused-malicious-attachments.html
- Boan News, "EPS vulnerability attacks still targeting public agencies and firms" (2018.11.23): https://m.boannews.com/html/detail.html?idx=74890
- Seculetter, "Kimsuky (APT43) HWP+LNK chain — full TTP dissection of Korean public/security targeting" (2026.04.21): https://seculetter.com/content-security/blog/a12-kimsuky-hwp-lnk/
- Seculetter, "HWP/HWPX zero-day chronology 2020–2026" (2026.04.18): https://seculetter.com/content-security/blog/a11-hwpx-zeroday-timeline/
Vulnerabilities and joint advisories
- NVD, CVE-2025-29867: https://nvd.nist.gov/vuln/detail/CVE-2025-29867
- FBI, State, NSA, NIS, Korean National Police, MOFA joint advisory, "North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media" (2023.06.01): https://media.defense.gov/2023/Jun/01/2003234055/-1/-1/0/JOINT_CSA_DPRK_SOCIAL_ENGINEERING.PDF
- CISA, FBI, USCYBERCOM joint advisory AA20-301A, "North Korean Advanced Persistent Threat Focus: Kimsuky" (2020.10): https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a
Open-document transition policy
- Byline Network, "Government moves to restrict hwp attachments on public document networks" (2026.04.23): https://byline.network/2026/04/23-586/
- Herald Economy, "Public sector to restrict 'hwp attachments' from May" (2026.04.23): https://www.heraldk.com/article/2026042316000053545
- Money Today, "Hangul files AI cannot read" (2026.06): https://www.mt.co.kr/article/2026052623275813425
- Digital Daily, "[2025 National Audit] Digital Galapagos — '90% of government documents are a black box AI cannot read'" (2025.10.14): https://www.ddaily.co.kr/page/view/2025101415400444080
- Byline Network, "Hangul now saves as HWPX, not HWP" (2021.04.15): https://byline.network/2021/04/15-117/
- Digital Today, "韩国5月起限制公共文书流通使用HWP,推动转向HWPX" (2026.04.24): https://www.digitaltoday.co.kr/cn/view/50599/
Memory-safe language migration
- Microsoft Security Response Center, "A proactive approach to more secure code" (2019): https://msrc.microsoft.com/blog/2019/07/a-proactive-approach-to-more-secure-code/
- Google Security Blog, "Eliminating Memory Safety Vulnerabilities at the Source" (2024.09): https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html
- CISA et al., "The Case for Memory Safe Roadmaps" (2023.12): https://www.cisa.gov/resources-tools/resources/case-memory-safe-roadmaps
- White House ONCD, "Back to the Building Blocks: A Path Toward Secure and Measurable Software" (2024.02): https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdf
- DARPA, "TRACTOR: Translating All C to Rust": https://www.darpa.mil/research/programs/translating-all-c-to-rust