The North Korean state-sponsored hacking group Kimsuky targeted South Korean military and corporate entities throughout March and April 2026 using sophisticated social engineering and HTTPSpy malware variants.
Key Points
- Kimsuky impersonated security software installers and Cisco Webex meeting pages to distribute malicious payloads to South Korean organizations.
- The attacks utilized HTTPSpy, a remote access trojan capable of capturing screenshots, executing shell commands, and exfiltrating sensitive data from compromised endpoints.
- Attackers leveraged stolen meeting schedules to create convincing lures, specifically targeting messaging administrators and service members.
- New technical methods include "JSONPing" for real-time infection verification and the abuse of legitimate Microsoft VS Code tunneling for persistent remote access.
- The group continues to evolve its toolkit, incorporating Rust-based malware like HelloDoor and HttpMalice, which are reportedly developed with the assistance of large language models.