discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

Kimsuky is using fake software and meeting pages to spread HTTPSpy and other malware. The group is also adopting VS Code tunnels, Cloudflare Quick Tunnels, and DWAgent in newer campaigns.

By Ravie Lakshmanan·May 29·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
Image: thehackernews.com

ENKI and Kaspersky both describe Kimsuky expanding its playbook in 2026, mixing social engineering with multiple delivery chains. The group is using fake security-install pages and spoofed Webex pages to push HTTPSpy, while also leaning on legitimate tunneling tools and new malware families like HelloDoor.

Why it matters

This shows a state-backed actor refining both its deception and its tooling to reach South Korean military and corporate targets. It also highlights how legitimate remote-access services and developer tools can be repurposed for persistence and post-compromise control.

Kimsuky is like a thief who keeps changing costumes. Instead of kicking doors in, it makes fake websites that look like real ones so people will click the wrong thing.

When someone falls for it, the bad software sneaks onto the computer and quietly sets up a way back in later. It can also wait, watch, and ask a secret control room for more instructions.

The group is also using normal tools in sneaky ways, like using a real hallway meant for helpers to move around a building. That makes the attack harder to notice, because the tools themselves are not obviously bad.

Analysis

Kimsuky’s delivery tactics

ENKI says Kimsuky targeted South Korean military and corporate entities in March and April 2026 with carefully tailored lures. One campaign used a fake security-software installation page for a South Korean B2B messaging service, while another copied a Cisco Webex page and pushed a fake camera-fix script.

The fake installer page offered two supposed security tools, then delivered executables that were actually meant to launch a second-stage DLL through regsvr32.exe. That DLL set persistence with a scheduled task, then reached out to a command-and-control server for more payloads. ENKI says the attacker may have watched repeated GET requests and only sent payloads to selected victims.

The Webex-themed campaign followed a different path. A ZIP file contained an encrypted JSE script that launched a downloader with PowerShell, performed anti-analysis checks, and fetched later-stage malware. The final stage dropped a loader that executed HTTPSpy on the victim machine. HTTPSpy is described as a full-featured RAT with shell execution, file transfer, process launching, screenshot capture, DLL injection, and self-deletion.

Broader tooling shift

Kaspersky says Kimsuky is also using VS Code tunneling, Cloudflare Quick Tunnels, DWAgent, LLMs, and Rust in recent activity. Those techniques affected public and private organizations in South Korea. The firm links the operator to droppers in JSE, PIF, SCR, and EXE formats that deliver PebbleDash and AppleSeed families.

Among the payloads is HelloDoor, a Rust-based PebbleDash variant first seen in August 2025 and possibly built with help from an LLM. The article also notes that HTTPSpy is not new: CrowdStrike tied it to credential-phishing activity against a German defense manufacturer in 2024, and its first use dates back to 2022.

Key points

  • Kimsuky used fake security-install and fake Webex pages to deliver malware in March and April 2026.
  • ENKI says the campaign delivered HTTPSpy through staged downloads, DLL loading, and persistence tasks.
  • HTTPSpy can run commands, move files, capture screenshots, inject into processes, and erase itself.
  • Kaspersky says Kimsuky is also using VS Code tunnels, Cloudflare Quick Tunnels, DWAgent, LLMs, and Rust.
  • The article links newer malware activity to PebbleDash, AppleSeed, and HelloDoor.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritythreat-intelligenceendpoint-securitymalwarenorth-koreacybercrime

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

May 29, 2026

Source

thehackernews.com

Share

Topics

securitythreat-intelligenceendpoint-securitymalwarenorth-koreacybercrime

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…