#HttpSpy

Malware/Tool

2026-05-27 • Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant

HttpSpy is the final payload in a Kimsuky campaign targeting South Korean military and corporate environments through April 2026. A new variant uses a three-stage installer, loader, and main-module execution chain instead of the earlier single-binary structure. Delivery involved tailored social engineering through fake security-software installation pages and a spoofed Webex meeting page based on a legitimate schedule. A JSE dropper created a decoy meeting page, decoded a DLL with certutil, and ran it through regsvr32. The downloader checked for virtualized environments and analysis tools, while command-and-control traffic used RC4 encryption followed by Base64 encoding.

Tagged Reports

« Back