Hangul 815 special-edition CD

HanCom Solutionware. The code that became Korea's national word processor lasted thirty years. North Korea spent those years probing the seams.

Dennis Kim former Cyworld CEO / 10 October 2026

🌐 한국어 · English · 日本語 · 中文

Classification: TLP:CLEAR | Type: Analytical Column | Date: 2026-10-10 Severity: HIGH | Confidence: A2 | Actors: APT37 · Kimsuky

Code does not age. The people who understand it do. A domestic word processor that became Korea's document infrastructure — and the unfinished work left by thirty-year-old code.

Master version (9 October 2026)

Opening — This month, HWP is blocked on civil-servant mail

If the government plan holds, October 2026 is when HWP attachments are restricted on the public-official integrated mailbox that civil servants use with citizens. Local-government Onnara systems already expanded HWPX mandates from 18 May. The official reason is "documents AI can read." There is another reason that barely appears in press releases. For more than a decade, HWP has been the most reliable door for North Korean hacking.

In December 2025, Genians Security Center published APT37's Operation Artemis. Operators posed as university professors or broadcast writers, built trust over several conversations, then sent HWP files dressed as interview questionnaires or event notices. Infection started when the victim opened the document, allowed content to run, and clicked a "hyperlink" in the body. That link was an OLE object painted to look like a link.

38 North, in an October 2025 report, diagnosed the fact itself — that HWP is the de facto standard across Korean ministries, the military, core industry, and academia — as a cyber-security weakness for South Korea and the U.S.–ROK alliance.

Why Hangul, of all software? This column answers in three layers — history, culture, technology — and then the problem almost no one discusses in earnest: thirty-year-old C code, and the aging of the people who still understand it.

1. A word processor born for Korean

Hangul Word Processor was started in 1988 by Lee Chan-jin, Kim Hyung-jip, Woo Won-sik, Kim Taek-jin and others from a Seoul National University computing club, and shipped as version 1.0 in 1989. The product name ᄒᆞᆫ글 keeps the obsolete vowel arae-a (ㆍ). Hangul and Computer (Hancom) was founded in 1990 and commercialized the product in earnest.

Foreign word processors of the time could not handle Korean properly. A Hangul syllable is an onset–nucleus–coda cluster; modern Hangul alone has 11,172 syllables. Hangul Word Processor met that problem head-on with johap-hyeong (combining) codes, then added mixed Hangul–Hanja, vertical writing, and Korean paragraph and tracking control, and became the "people's word processor."

Korean is an agglutinative language of particles and endings, mixing Sino-Korean with native words; official and academic documents are thick with mixed-script Hanja and special symbols. Hangul answered that typesetting demand first and most accurately. Microsoft Word knocked on the Korean market in the mid-1990s and did not clear the wall of Korean layout quality and user habit. The "Defend Hangul" campaign against Microsoft's investment offer during the 1998 financial crisis showed that this software was more than a product in Korean society.

That same symbolism later became an opportunity for attackers.

2. A country of tables — and why the format became "Korea-only"

The table culture of official documents

Korean administrative documents are defined by tables and gaejosik (itemized bureaucratic prose). Drafts, reports, plans, budgets, even one-page situation notes mostly split items into cells and fill them with sentences ending in "함" or "임." Cell merges, border weights, line spacing, fonts and compression ratios are prescribed; a slight miss earns "do it again" — a long-standing landscape of public service.

Hangul was overwhelming at this table editing. Drawing complex tables, splitting and merging cells, even calculating inside a table became the work method of civil servants and researchers itself.

Why only Korea uses HWP — political-economic lock-in

Features are not enough. HWP's dominance has been held by several layers of lock-in, along with national sentiment.

  • System lock-in. The government work-management system Onnara used HWP as the default document format. Because civil servants used HWP, vendors, research institutes, and schools had to submit in HWP.
  • Template-asset lock-in. Decades of official forms, grant applications, and bid templates are all HWP. Changing the format means remaking tens of thousands of forms.
  • Procurement and industrial policy. Under the banner of nurturing domestic software, Hancom Office was long the default in public procurement.
  • Symbolic lock-in. The narrative of "domestic software standing up to foreign products" made conversion emotionally harder.

From an attacker's view this structure is decisive. A file format the target opens every day, a format nobody distrusts when opening, and a format that in practice only Korea uses. Those three conditions meet at HWP. Microsoft Word and PDF are watched by the global security industry; HWP is watched, in practice, only by Korean security. Attacks collect where fewer eyes are looking.

"G7 summit — BH policy changes"

If a document with that title arrived as HWP by mail or KakaoTalk, almost no bureaucrat would refuse to click.

3. The character of the defects — two attack axes

Attacks on HWP split into two branches of completely different character. Mix them up and the prescription points at the wrong place.

First — memory defects: the document is owned the moment it is "read"

The legacy HWP 5.0 format stacks proprietary binary records, compressed, on Microsoft's OLE Compound File. Hancom has published format specs, but more than thirty years of backward-compatibility demands leave the parser with an enormous number of exceptions and branches. A complex binary parser is a wide attack surface.

Public vulnerabilities show a clear pattern.

Period Identifier Type Notes
2015 CVE-2015-6585 Type confusion FireEye confirmed as a North Korea–linked zero-day; Hancom patched 7 September
2016–2020 CVE-2017-8291 and others Embedded Ghostscript (EPS) bugs An external C library that rendered EPS pictures inside HWP became a path
2022 CVE-2022-33896 Buffer underflow Memory defect in XML-based document parsing
Published 2026.02 CVE-2025-29867 Type confusion (CWE-843) Hancom Office 2018·2020·2022·2024 entire line, CVSS 4.0 8.5. No confirmed in-the-wild abuse at disclosure

Type confusion, buffer overflow/underflow, and use-after-free are all defects typical of memory-unsafe languages such as C/C++. Patch one and a cousin appears elsewhere. This is not one developer's mistake; it is a language and architecture problem. Ghostscript shows the problem is not only in Hancom's own code. An external C library pulled in to draw a picture inside a document can be an attack point too.

Second — abuse of a normal feature: no bug required

HWP can embed OLE objects. The original purpose is tables, pictures, and data from other programs. In Operation Artemis the operators disguised an OLE object as an ordinary hyperlink. Even if the software has zero bugs, infection completes when the user ignores a warning and clicks once. Dropping a shortcut (.lnk) with an HWP icon inside an archive is the same family.

The core of this axis is not technology but trust. Operators impersonate professors, reporters, broadcast writers, or research-institute staff and talk for weeks before sending a file.

The two axes demand different prescriptions

Axis A: memory defects Axis B: abuse of normal features
Moment of attack The instant the document is opened (parsed) The instant the user allows / clicks
Representative cases CVE-2015-6585, EPS/Ghostscript Operation Artemis, HWP+LNK
Stopped by a patch? Individual bugs yes; the family repeats No (the feature itself is normal)
Root prescription Memory-safe language migration, sandbox CDR / document inspection, user behavior

An HWP rewritten in Rust still falls if the user clicks a disguised link. Conversely, no amount of training stops a zero-day that executes on open. Either one alone is not enough.

4. Thirteen years of North Korean HWP targeting

Period Actor Content Axis
2013 Kimsuky Kaspersky first published the Kimsuky campaign. Included a dedicated module to steal HWP documents. Before it was an intrusion tool, HWP was a collection target Collection
2015 Suspected DPRK-linked FireEye published HWP zero-day CVE-2015-6585 and the Hangman backdoor. C2 overlapped other suspected DPRK operations A
2016–2020 Multiple DPRK-linked Years of HWP lures with malicious EPS, disguised as unification/security seminar material or virtual-asset documents A
2017 APT37 HWP spearphishing against ~20 people in diplomacy, security, unification A+B
2023 Kimsuky Six U.S. and Korean agencies (FBI, State, NSA; NIS, National Police, MOFA) issued a joint advisory. Warned of social engineering posing as reporters and scholars B
2025.03 APT37 Operation ToyBox Story. LNK files disguised as HWP against North Korea–related activists B
2025.08–11 APT37 Operation Artemis. Professor/broadcast-writer impersonation, OLE hyperlink disguise, steganography plus DLL side-loading B

The chronology is clear. Through the mid-2010s Axis A (vulnerabilities) was the main effort. As Hancom patched faster and embedded Ghostscript was removed, weight moved to Axis B (social engineering and trusted-feature abuse). The 2023 U.S.–ROK joint advisory stressed that Kimsuky does not attach malware to the first mail, and spends a long time building trust.

5. North Korea still hunts HWP

North Korean HWP attacks are not past tense. In 2026 the industry still reports variants that combine HWPX with script files (JSE), and Kimsuky chains that weave HWP with LNK.

One more point. Operators already use HWPX as bait. Switching to an open format does not end this war. They follow not the format but the work flow the target trusts. If Korean public agencies use HWPX, the lure becomes HWPX. If official mail is blocked, they move to messengers and cloud links.

6. What we should do

Prescriptions must be designed for both axes. This column proposes four. The first two address Axis A, the third Axis B, the fourth organizations and individuals.

First, move thirty-year-old C code to a memory-safe language [Axis A]

This is the part of the column I most want emphasized.

Hangul's roots are late-1980s DOS-era C. It expanded to C/C++ through the Windows era, and more than thirty years of features and compatibility code were layered on top. Direct pointers and hand-allocated memory were then the best choice for performance. Today that code is the point North Korea has been digging for more than a decade. At one time they even rendered without MFC, because GDI differed by Windows version.

Then the human problem. The first-generation developers of Hangul are now around sixty, and most left the company long ago. People who deeply understand the original design and internals shrink, while the code stacked on top keeps growing. Code does not age, but the people who understand it do. The greatest risk in a legacy system is this break in knowledge.

The world's direction is already set.

  • Microsoft has said about 70% of the security vulnerabilities it patches in its own products each year are memory-safety issues.
  • Google reported that after writing new Android code in Rust and other memory-safe languages, memory-safety bugs as a share of all vulnerabilities fell from 76% in 2019 to 24% in 2024. The core point: changing only new code, without rewriting all existing C/C++, already worked.
  • CISA, NSA, FBI and allied cyber agencies jointly recommended in 2023 that software makers write a "memory-safe roadmap"; the White House ONCD officially urged a shift to memory-safe languages in 2024.
  • DARPA is pushing TRACTOR, using AI to automatically convert C to Rust.

Moving millions of lines of C used to be unrealistic. There is now a new tool: LLM-based code migration. A realistic order:

  1. Move the parser first. Axis A attacks happen the moment a document is "read." Rewrite HWP/HWPX parsers and image/OLE modules — the boundary code that takes external input — in Rust.
  2. Convert with AI, verify with tests. An LLM does a first-pass C-to-Rust conversion; differential testing and fuzzing run millions of the same documents through old and new engines. Hancom has a thirty-year corpus of real documents no other company has. The LLM is a translator, not a judge. Tests judge.
  3. Cage remaining C. Isolate what cannot move yet in a sandbox so a breach does not become a system-wide fire.
  4. Leave knowledge as code. Documenting legacy behavior with LLMs during conversion, and pinning it with tests, preserves first-generation tacit knowledge in a form the next generation can read.

Who pays? Honestly, this work is large for Hancom alone. Firms do not spontaneously spend tens of billions of won on a security rewrite that does not grow revenue. But as long as HWP is national document infrastructure, this is not one company's quality problem; it is national cyber security. Two levers are needed.

  • Procurement conditions. Require a memory-safe roadmap for document software public agencies buy — the same way the United States ties Secure by Design to procurement.
  • Joint R&D. Support parser rewrite and fuzzing infrastructure as national R&D, and open-source part of the result (especially an HWPX parser) so the whole security industry can verify it.

Second, push the open-document transition all the way. Shrink the exposure of a single word processor.

The government mandated HWPX on central-ministry Onnara in 2022 and expanded it to local government from 18 May 2026. On-mail between officials and the citizen-facing official mailbox restrict HWP attachments from October. HWPX follows the XML open document standard (OWPML, KS X 6101); rename the extension to zip and the internals are readable as-is.

The real value of the switch is inspectability. Structure must be transparent for automated inspection, CDR, and AI analysis. As above, an open format is not a safe format. Parsing bugs have been reported in HWPX, and operators already use it. Format conversion is a starting line, not a finish.

Third, build an LLM-based document inspection stack

If the LLM in the first item is a tool that repairs code, the LLM here is a tool that inspects incoming documents. Same technology, different job.

Axis B is hard to catch with signatures. It is not malware; it is a normal feature plus a plausible context. So inspection that reads context is needed. After structurally extracting OLE objects, external links, scripts, and metadata from HWPX, an LLM can ask:

  • "If this is an interview questionnaire, why is there an executable object inside?"
  • "Does the link text in the body match the actual destination?"
  • "Do the affiliation of the alleged professor-sender and the document's style and metadata match?"

Even here the LLM is not the final judge. A deterministic engine confirms risk elements; the LLM filters suspicion upstream and explains in language a human can understand. Moving decades of old HWP into HWPX or structured data is also a base for this inspection stack and for public-data use.

Fourth, organizations default to CDR; individuals keep five habits [org · individual]

Organizations. CDR (Content Disarm and Reconstruction) strips executable elements — OLE objects, scripts, external links — and rebuilds a safe document. It works whether a vulnerability is known or not, so it hits both Axis A zero-days and Axis B disguised links. Documents from outside should open only after CDR, as the mail-gateway default.

Individuals. Policy and technology take years to change. What North Korea is aiming at in the meantime is one person's click.

Five things you can do from today

  1. If a professor, reporter, or writer contacting you for the first time sends a document, confirm once through a channel you already know. The 2023 U.S.–ROK joint advisory recommended a short video call to confirm identity — even if that means a bare-face video call.
  2. If opening a document shows "Enable Content" or "Run," do not click. A normal report or questionnaire does not ask that permission.
  3. A link or icon inside a document is not the document. If you must, inspect the URL yourself and type it into a browser separately.
  4. Turn on "show file extensions" in Windows Explorer. A .lnk wearing an HWP icon is not a document; it is an executable.
  5. Keep Hancom Office current, and replace versions that are out of support. If you received a suspicious document, report it to KISA (118) or the National Intelligence Service (111).

7. Anticipated objections and replies

Then why not just switch to Microsoft Word?Word-adoption talk has even appeared among civilian members of the National AI Strategy Committee. Switching to Word does not remove a single attack axis; itmoves you onto another company's C++ parser. Word has long been a regular path for macro and OLE abuse. You also have to count the cost of throwing away decades of public templates and Korean typesetting assets, and the risk of parking national core document infrastructure on one foreign firm. The question is not "domestic or foreign" but inspectable and memory-safe? If that bar is met, HWPX, DOCX, or ODF will do. HWPX is the realistic starting point because it moves existing template assets with the least loss.

What about conversion costs for civil servants and researchers?They are not small. Old forms break, users on old versions cannot open files, and inter-ministry system links need work. That is why the government chose a staged approach: five months of grace on official mail, starting with notice pop-ups. Conversion costs are real, but the comparison changes againstthirteen years of intrusion costs.

Has Hancom done nothing?No. Hancom has supported HWPX since 2010 and made HWPX the default save format in a 2021 regular patch. Around 2018 it removed the embedded Ghostscript module that had become an attack path, and it issues patches through KrCERT/CC when vulnerabilities are reported. The point of this column is not that Hancom has not tried, but thatpatches and format conversion as they currently exist cannot end a defect family at the language level. The next step is changing the foundation of the code.

Does switching to Rust end North Korean hacking? No. As chapter 3 showed, Rust shrinks Axis A; it does not stop Axis B clicks on disguised links. That is why the four prescriptions are one bundle.

Closing

In 1989, when foreign software could not handle Hangul, a handful of university students changed how this country writes documents in Korean. The C they wrote has held up administration, research, and industry for more than thirty years.

That code still runs as it did then. What changed is the world outside. North Korea has been digging its seams for thirteen years, and the people who first designed it have been leaving the field one by one. This October, when HWP is blocked on civil-servant mail, must be a beginning, not an end. After the format, change the code. After the code, leave the knowledge for the next generation.

If 1989's students had C, 2026's we have AI and memory-safe languages. Rewriting Hangul is not throwing the inheritance away. It is making that inheritance last another thirty years.

References

North Korean HWP attack cases

Vulnerabilities and joint advisories

Open-document transition policy

Memory-safe language migration