news.mlab.sh
Back to the feed
threat-intel

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

High
Summary

North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 2026. The group employs sophisticated social engineering, including fake Webex meetings and security software installations, to deliver malware payloads like MemLoader.dll and mTSTCv8.mdxm, ultimately aiming to establish persistent remote access. This campaign highlights Kimsuky's ongoing evolution and adaptation of techniques, including the use of JSONPing for real-time infection verification.

Kimsuky’s recent activity, observed between March and April 2026, involved a multi-faceted approach to compromise South Korean targets. The group leveraged HTTPSpy, a remote access trojan, disguised as legitimate security software installers, to deliver malware payloads. This tactic, previously used since 2023, involved creating fake web pages mimicking South Korean B2B messaging service installations, specifically targeting administrators within corporate environments. The malware, including MemLoader.dll and mTSTCv8.mdxm, established persistence via scheduled tasks and communicated with C2 servers to download further payloads. The group’s use of JSONPing for real-time infection verification demonstrates a sophisticated approach to maximizing delivery success.

Alongside HTTPSpy, Kimsuky also utilized a counterfeit Cisco Webex page to lure victims into downloading and executing a malicious JavaScript file, resulting in the deployment of an intermediate downloader and ultimately, the HTTPSpy payload. This campaign further showcases Kimsuky’s ability to mimic legitimate services and exploit user trust. The group’s adaptation of VS Code tunneling, alongside other tools like Cloudflare Quick Tunnels and DWAgent, indicates a continued evolution in their techniques and a focus on establishing persistent access to compromised systems.

The broader context of this activity is underscored by CrowdStrike's 2025 European Threat Landscape Report, which highlighted Kimsuky's prior targeting of a German defense manufacturer. This ongoing activity demonstrates Kimsuky's persistent threat profile and their willingness to adapt their methods across different targets and geographies.

Read the full article at The Hacker News