Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종

2026-05-27 ENKI Analysis of Kimsuky's Advanced Attack Techniques: JSONPing, Webex Impersonation, and a New HttpSpy Variant

https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant

Thumbnail for Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종

ENKI Whitehat identified Kimsuky malware delivery activity through April 2026 against South Korean military and enterprise-related targets. The campaigns used tailored lures, including fake domestic security software installation pages and a fake Webex meeting page built around a real meeting schedule. ENKI documented JSONPing, a JSONP-based localhost callback technique used by distribution pages to check whether malware is already running on the victim host. In the Webex chain, the final payload was a new HttpSpy variant using a three-stage installer, loader, and main module flow, with links to Kimsuky supported by reused RC4 keys, infrastructure, code patterns, export names, and certificate reuse.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN appview.imagetemplate.com 2026-05-27 2026-05-27
HASH 9de541b039cfdb96c7810df49efd958… 2026-05-27 2026-05-27
HASH 1efaf988fded55cd3b974c66f4ca8f7e 2026-05-27 2026-05-27
HASH bd8e948a6e61436532cd2ed2b62db3f3 2026-05-27 2026-05-27
HASH a762d65c0d6f6345541485aeef35a3b… 2026-05-27 2026-05-27
HASH 3369b911cf3706a2660d2af9b3c35f9a 2026-05-27 2026-05-27
HASH ca42cba2782a0b6952dd0425fa08cbd… 2026-05-27 2026-05-27
HASH 1d8e50ec756e88025c5248cfaa6ee70… 2026-05-27 2026-05-27
HASH fcaf03060e34a73fe499b906492d9f13 2026-05-27 2026-05-27
HASH c089457d5f4b22313b927bb36a320f8… 2026-05-27 2026-05-27
HASH 8833a270ddef0f464d5916958b6778e6 2026-05-27 2026-05-27
HASH be978477fe7c179cb9607a6e08a05dff 2026-05-27 2026-05-27
HASH 9df5ca76ac085b89c1ddcb3963e9fe97 2026-05-27 2026-05-27
HASH 784d9273c75e983f2b4730d1f2198cc… 2026-05-27 2026-05-27
HASH 50f619aaba1d28882022ced135b13a07 2026-05-27 2026-05-27
HASH c6de1be41dcfbad9cae76c58eae7f5a3 2026-05-27 2026-05-27
HASH c61a6efe1a169c6c1d8595af3ff0dd74 2026-05-27 2026-05-27
HASH be31a38bab026f229afd5e3174c363f7 2026-05-27 2026-05-27
HASH b4dd4c76d7deef4cf532e240b7f84c9d 2026-05-27 2026-05-27
HASH 6d2dfd7ca77530afec000a197d6b8677 2026-05-27 2026-05-27
HASH 0d07fb6d1a3736ea543ab8364115e435 2026-05-27 2026-05-27
HASH ea5f32e1273ec93d43ee09a337fb60e1 2026-05-27 2026-05-27
HASH bea602695d58cbf25fff058834e36c1d 2026-05-27 2026-05-27
HASH 144f303504538fb7d65e2f103ab2338… 2026-05-27 2026-05-27
HASH cc837d2b2af4bd9c1c3faf61cefeb848 2026-05-27 2026-05-27
HASH 9fd46aa45ac8539cd288b744730661b… 2026-05-27 2026-05-27
HASH 4a476abcf741323b367eda0ec49f8c38 2026-05-27 2026-05-27
IPv4 27.102.113.106 2026-05-27 2026-05-27
IPv4 157.250.202.123 2026-05-27 2026-05-27
DOMAIN bigfile.jaycloudlab.com 2026-05-27 2026-05-27
URL https://bigfile.jaycloudlab.com… 2026-05-27 2026-05-27
URL https://load.erasecloud.n-e.kr/… 2026-05-27 2026-05-27
URL https://pipeline.embeddedonline… 2026-05-27 2026-05-27
DOMAIN pipeline.embeddedonline.org 2026-05-27 2026-05-27
URL https://pipeline.embeddedonline… 2026-05-27 2026-05-27
DOMAIN hdrgdrfes.chickenkiller.com 2026-05-27 2026-05-27
URL http://hdrgdrfes.chickenkiller.… 2026-05-27 2026-05-27
URL https://download.birdriver.org/… 2026-05-27 2026-05-27
DOMAIN download.birdriver.org 2026-05-27 2026-05-27
URL https://download.birdriver.org/… 2026-05-27 2026-05-27
DOMAIN conference.birdriver.org 2026-05-27 2026-05-27
URL https://conference.birdriver.or… 2026-05-27 2026-05-27
DOMAIN load.serverpit.com 2026-05-27 2026-05-27
URL https://load.serverpit.com/fwri… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
DOMAIN ibizplus.n-e.kr 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/ins… 2026-05-27 2026-05-27
DOMAIN load.erasecloud.n-e.kr 2026-05-14 2026-05-27

Related Actors

Related Reports

2026-04-17 • 45% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, T1140, T1041
« Back