Kimsuky Expands Cyber Arsenal with HTTPSpy, HelloDoor, and VS Code Tunnels in Recent Attacks

Published:

spot_img

Kimsuky Expands Cyber Arsenal with HTTPSpy, HelloDoor, and VS Code Tunnels in Recent Attacks

Recent cyber operations attributed to the North Korean state-sponsored threat actor Kimsuky, also known as Velvet Chollima, have intensified, targeting South Korean military and corporate entities throughout March and April 2026. This escalation highlights Kimsuky’s evolving tactics and the sophistication of its cyber capabilities.

Kimsuky has employed a variety of social engineering techniques, including the spoofing of security software installation pages and the creation of counterfeit Webex meeting pages that exploit legitimate meeting schedules. According to ENKI, a cybersecurity firm, these tactics are indicative of a calculated approach to deceive victims into downloading malicious software disguised as legitimate applications.

The HTTPSpy Malware Campaign

The recent attacks have been linked to a variant of malware known as HTTPSpy, which Kimsuky has disguised as installers for South Korean security software. This tactic has been a consistent element of Kimsuky’s strategy since 2023. In the latest observed campaign, malicious payloads were delivered through a fraudulent webpage that mimicked the security software installation page of a South Korean B2B messaging service. The nature of this lure suggests a targeted effort to compromise messaging administrators within corporate environments.

The fraudulent page claimed to offer two security tools: a firewall and a keyboard security program. When users initiated the download, they inadvertently downloaded executables named “nos-setup.exe” and “astx-setup.exe,” which masquerade as nProtect Online Security and AhnLab Safe Transaction (ASTx). Despite their differing names, both executables exhibit identical malicious behaviors.

The primary function of these binaries is to launch a second-stage DLL payload, “MemLoader.dll,” via “regsvr32.exe.” Following this, a batch script is executed to delete the original files from the disk. The DLL establishes persistence on the host through a scheduled task and connects to a command-and-control (C2) server to retrieve additional payloads.

ENKI noted that the attacker likely monitored recurring GET requests from the malware, selectively delivering payloads to specific victims.

Exploiting Webex and JavaScript

In a separate campaign observed in April 2026, Kimsuky utilized a counterfeit webpage resembling Cisco Webex to prompt victims to download and execute a script intended to resolve camera access issues. This action led to the retrieval of a ZIP archive containing an encrypted JavaScript (JSE) file named “fix-camera.jse.”

Executing this JSE file deploys an intermediate downloader, “mTSTCv8.mdxm,” using PowerShell. This downloader conducts anti-analysis checks and contacts a C2 server to fetch subsequent malware, either “engine.dat” or “spyInster.dll.” Ultimately, the DLL drops a loader component, “cacheMon.dat,” which executes HTTPSpy on the compromised system.

HTTPSpy is a comprehensive remote access trojan (RAT) that enables a wide range of functionalities, including executing shell commands, file uploads and downloads, process execution, screenshot capture, and self-erasure from the endpoint.

Historical Context and Previous Deployments

This is not the first instance of Kimsuky deploying HTTPSpy. The malware was previously reported in CrowdStrike’s 2025 European Threat Landscape Report, which indicated that Kimsuky targeted employees of a German defense manufacturer through a credential phishing campaign between May and September 2024. The initial deployment of HTTPSpy dates back to 2022.

In addition to the malware, Kimsuky also drops an HTML file named “meeting.html,” which redirects victims to a legitimate Webex meeting room associated with an actual scheduled event. This indicates that the attacker may have compromised a service member’s device or account to obtain the meeting schedule, subsequently crafting a fake meeting page to distribute malware to other attendees.

ENKI has identified additional fake webpages that query a local server established by the malware on the victim’s machine via JSONP (JSON with Padding) to verify malware execution status and prompt installation if it is not running. This technique, referred to as JSONPing, remains active, although the specific nature of the downloaded malware is currently unknown.

Evolving Tactics: HelloDoor and HttpMalice

Recent disclosures from Kaspersky have detailed Kimsuky’s use of Microsoft Visual Studio Code (VS Code) tunneling, Cloudflare Quick Tunnels, and the Rust programming language in its latest campaigns. This evolution underscores Kimsuky’s adaptability and the increasing complexity of its operations.

Kaspersky reported that Kimsuky has leveraged legitimate VS Code tunneling mechanisms to establish persistence and has distributed the open-source DWAgent remote monitoring and management tool for post-exploitation activities. These operations have affected various sectors in South Korea, impacting both public and private entities.

The attack chains have utilized a range of droppers written in JSE, PIF, SCR, and EXE formats to deliver two primary malware families: PebbleDash and AppleSeed. While PebbleDash has targeted defense organizations in Brazil and Germany, the AppleSeed cluster has primarily focused on government entities.

Key Malware Families

The malware families delivered by Kimsuky include:

  • HelloDoor: A Rust-based variant of PebbleDash first identified in August 2025, likely developed using a large language model (LLM). It supports basic functionalities such as setting the current directory and executing commands.
  • HttpMalice: The latest backdoor variant of PebbleDash, emerged no later than December 2025. It can gather system information, establish persistence, perform reconnaissance, capture screenshots, and exfiltrate execution outputs.
  • HttpTroy: A backdoor delivered via a loader named MemLoad, allowing file uploads/downloads, command execution, and process termination.
  • AppleSeed: Available in two variants: Dropper and Spy. The Dropper downloads additional malware and executes commands from its C2 server, while the Spy version gathers sensitive information, including documents and keystrokes.
  • HappyDoor: An advanced version of AppleSeed that first surfaced in 2021.

Strategic Shifts in Cyber Operations

Kimsuky’s recent tactics reflect a significant shift in its operational strategy. The use of legitimate VS Code Remote Tunneling for covert remote access eliminates the need for traditional malware-based C2 channels. This approach has been corroborated by multiple cybersecurity firms, indicating a broader trend in advanced persistent threat (APT) operations.

Kaspersky’s analysis reveals that Kimsuky retains access to the original source code of its malware clusters, allowing for ongoing modifications. The overlapping target sectors of these clusters include defense, military, government, medical, machinery, and energy industries.

The AppleSeed cluster has shifted its focus toward data exfiltration, with GPKI certificate extraction emerging as a notable capability. Meanwhile, the PebbleDash cluster showcases advanced remote control functionalities and an expanding array of targets.

For further insights into Kimsuky’s evolving tactics and the implications for cybersecurity, refer to the original reporting source: thehackernews.com.

Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.

spot_img

Related articles

Recent articles

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers The recent cyberattack on Odido, a major Dutch telecom provider,...

Cybersecurity Researchers Uncover “Ghostcommit”: A New Image-Based Attack Manipulating AI to Steal Sensitive Data

Cybersecurity Researchers Uncover "Ghostcommit": A New Image-Based Attack Manipulating AI to Steal Sensitive Data Cybersecurity researchers have identified a sophisticated supply chain attack technique dubbed...

Irvinder Singh Lail Appointed to Strengthen J.S. Held’s Global Capability Leadership

Irvinder Singh Lail Appointed to Strengthen J.S. Held's Global Capability Leadership In a significant move for the global consulting landscape, J.S. Held has appointed Irvinder...

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation In a landscape where cybersecurity threats are increasingly sophisticated, accurate...