#JSONPing
Malware/Tool
JSONPing is a delivery-page technique observed in Kimsuky campaigns targeting South Korean military and corporate personnel through April 2026. Tailored social engineering used pages impersonating domestic security-software installers and Webex meetings, including a fake page apparently built from a real victim's meeting schedule. The distribution page issued JSONP requests to a localhost server created by malware on the target system, allowing the page to determine in real time whether the victim had already executed the payload and to prompt installation when it had not. In the Webex-themed chain, the final payload was a new HttpSpy variant delivered through a three-stage installer, loader, and main-module sequence. Shared infrastructure, code patterns, and encryption keys supported attribution to Kimsuky.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days