#HttpSpy
Malware/Tool
2026-05-27 • Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
HttpSpy is the final payload in a Kimsuky campaign targeting South Korean military and corporate environments through April 2026. A new variant uses a three-stage installer, loader, and main-module execution chain instead of the earlier single-binary structure. Delivery involved tailored social engineering through fake security-software installation pages and a spoofed Webex meeting page based on a legitimate schedule. A JSE dropper created a decoy meeting page, decoded a DLL with certutil, and ran it through regsvr32. The downloader checked for virtualized environments and analysis tools, while command-and-control traffic used RC4 encryption followed by Base64 encoding.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days