AUTO-UPDATED

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored hacking group Kimsuky targeted South Korean military and corporate entities throughout March and April 2026 using sophisticated social engineering and HTTPSpy malware variants.

Key Points

  • Kimsuky impersonated security software installers and Cisco Webex meeting pages to distribute malicious payloads to South Korean organizations.
  • The attacks utilized HTTPSpy, a remote access trojan capable of capturing screenshots, executing shell commands, and exfiltrating sensitive data from compromised endpoints.
  • Attackers leveraged stolen meeting schedules to create convincing lures, specifically targeting messaging administrators and service members.
  • New technical methods include "JSONPing" for real-time infection verification and the abuse of legitimate Microsoft VS Code tunneling for persistent remote access.
  • The group continues to evolve its toolkit, incorporating Rust-based malware like HelloDoor and HttpMalice, which are reportedly developed with the assistance of large language models.

Why it Matters

These campaigns demonstrate a significant escalation in the sophistication of North Korean cyber espionage, moving beyond simple phishing to highly tailored, context-aware attacks. By exploiting legitimate software and stolen credentials, Kimsuky poses a persistent threat to the operational security of critical defense, government, and private sector infrastructure.
Internet Published by info@thehackernews.com (The Hacker News)
Read original