Skip to content

S0214 HAPPYWORK

HAPPYWORK is a downloader used by APT37 to target South Korean government and financial victims in November 2016. 1

Item Value
ID S0214
Type MALWARE
Version 1.0
Created 18 April 2018
Last Modified 17 October 2018
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1105 Ingress Tool Transfer can download and execute a second-stage payload.1
enterprise T1082 System Information Discovery can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.1
enterprise T1033 System Owner/User Discovery can collect the victim user name.1

Groups That Use This Software

ID Name References
G0067 APT37 1

References