Finding North Korean Software Part 1

I’ve been on the lookout for finding North Korean software. I’ve got a decent collection now. One of the things that I’ve been searching are sites where people are checking running processes. I found this the other day: http://windowfdb.com/i.php?q=ghusb-dll-c-windows-system32

I’ve never heard of the Golden Horse program but some more digging reveals that it’s  “a physical constitution characterization and diagnosis program”: https://books.google.com.sg/books?id=JIlh9nNeadMC&pg=PA249&lpg=PA249&dq=%22golden+horse%22+%22north+korea%22+-paektu+-award+-film+-awards&ots=gy_sDcyaaW&sig=ACfU3U0CciFH3au9bwWz8g2d7MD-H2-XMA&hl=en#v=onepage&q=%22golden%20horse%22%20%22north%20korea%22%20-paektu%20-award%20-film%20-awards&f=false

I haven’t been able to find a copy yet but it’s going on the list of things to watch for

North Korean Malware?

I noticed something interesting browsing through the source of the new DPRK portal site the other day. Specifically, this snippet:

<style>
	p{
	  font-family: '천리마', 'KP CheonRiMa', 'KWP ChonRiMa', 'PRK P Gothic';
	  margin-bottom: 0px;
	}
</style>

I had to Google it, but found the following on a Chinese forum

Screen Shot 2019-04-28 at 1.03.05 AM.png

KP CheonRiMa is a font developed in North Korea. Some further searching lead to the following:

Screen Shot 2019-04-29 at 12.44.45 AM.pngScreen Shot 2019-04-29 at 12.45.15 AM.png