Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
Kimsuky is using fake software and meeting pages to spread HTTPSpy and other malware. The group is also adopting VS Code tunnels, Cloudflare Quick Tunnels, and DWAgent in newer campaigns.
Intelligence analysis by GPT-5.4 Mini

ENKI and Kaspersky both describe Kimsuky expanding its playbook in 2026, mixing social engineering with multiple delivery chains. The group is using fake security-install pages and spoofed Webex pages to push HTTPSpy, while also leaning on legitimate tunneling tools and new malware families like HelloDoor.
Kimsuky is like a thief who keeps changing costumes. Instead of kicking doors in, it makes fake websites that look like real ones so people will click the wrong thing.
When someone falls for it, the bad software sneaks onto the computer and quietly sets up a way back in later. It can also wait, watch, and ask a secret control room for more instructions.
The group is also using normal tools in sneaky ways, like using a real hallway meant for helpers to move around a building. That makes the attack harder to notice, because the tools themselves are not obviously bad.
Analysis
Kimsuky’s delivery tactics
ENKI says Kimsuky targeted South Korean military and corporate entities in March and April 2026 with carefully tailored lures. One campaign used a fake security-software installation page for a South Korean B2B messaging service, while another copied a Cisco Webex page and pushed a fake camera-fix script.
The fake installer page offered two supposed security tools, then delivered executables that were actually meant to launch a second-stage DLL through regsvr32.exe. That DLL set persistence with a scheduled task, then reached out to a command-and-control server for more payloads. ENKI says the attacker may have watched repeated GET requests and only sent payloads to selected victims.
The Webex-themed campaign followed a different path. A ZIP file contained an encrypted JSE script that launched a downloader with PowerShell, performed anti-analysis checks, and fetched later-stage malware. The final stage dropped a loader that executed HTTPSpy on the victim machine. HTTPSpy is described as a full-featured RAT with shell execution, file transfer, process launching, screenshot capture, DLL injection, and self-deletion.
Broader tooling shift
Kaspersky says Kimsuky is also using VS Code tunneling, Cloudflare Quick Tunnels, DWAgent, LLMs, and Rust in recent activity. Those techniques affected public and private organizations in South Korea. The firm links the operator to droppers in JSE, PIF, SCR, and EXE formats that deliver PebbleDash and AppleSeed families.
Among the payloads is HelloDoor, a Rust-based PebbleDash variant first seen in August 2025 and possibly built with help from an LLM. The article also notes that HTTPSpy is not new: CrowdStrike tied it to credential-phishing activity against a German defense manufacturer in 2024, and its first use dates back to 2022.
Key points
- Kimsuky used fake security-install and fake Webex pages to deliver malware in March and April 2026.
- ENKI says the campaign delivered HTTPSpy through staged downloads, DLL loading, and persistence tasks.
- HTTPSpy can run commands, move files, capture screenshots, inject into processes, and erase itself.
- Kaspersky says Kimsuky is also using VS Code tunnels, Cloudflare Quick Tunnels, DWAgent, LLMs, and Rust.
- The article links newer malware activity to PebbleDash, AppleSeed, and HelloDoor.



