THREAT INTELLIGENCE REPORT

Kimsuky Expands Cyber Espionage Operations with HTTPSpy, HelloDoor, AppleSeed and VS Code Tunnels

Analysis of North Korean threat actor Kimsuky's latest cyber espionage campaign targeting South Korean military, government, defense, corporate, and critical infrastructure sectors using social engineering, HTTPSpy RAT, HelloDoor, AppleSeed malware, and legitimate remote access technologies.

Threat Actor
Kimsuky
Country
North Korea
Campaign Type
Cyber Espionage
Report Date
May 2026

Executive Summary

Kimsuky, also tracked as Velvet Chollima, conducted targeted cyber espionage operations against South Korean military and enterprise organizations throughout March and April 2026. The campaign leveraged fake software installers, counterfeit Cisco Webex meeting pages, social engineering, and multiple malware families to compromise victims and establish long-term persistence.

The threat actor deployed HTTPSpy remote access trojans, HelloDoor backdoors, AppleSeed spyware, HttpMalice, HttpTroy, and abused legitimate remote administration services such as Microsoft Visual Studio Code Remote Tunneling, Cloudflare Quick Tunnels, and DWAgent to evade detection and maintain access.

Key Assessment: Kimsuky continues to evolve beyond traditional malware deployment by combining social engineering, legitimate cloud services, remote management tools, Rust-based malware, and stolen meeting schedules to improve operational effectiveness.

Campaign Metrics

Threat Level

Critical

Threat Actor

Kimsuky

Primary Objective

Espionage

Target Region

South Korea

Malware Families

6+

Persistence

VS Code Tunnel

Threat Actor Profile

Category Details
Threat Group Kimsuky (Velvet Chollima)
Attribution North Korean State-Sponsored
Primary Objective Cyber Espionage
Victim Sectors Military, Government, Defense, Energy, Medical, Corporate
Target Geography South Korea, Germany, Brazil
Operational Period March-April 2026

Attack Timeline

Initial Social Engineering

Victims receive links to fake security software pages and counterfeit Webex meeting portals.

Malicious Installer Execution

Victims download fake security tools disguised as nProtect Online Security and AhnLab Safe Transaction.

Loader Deployment

MemLoader.dll is executed through regsvr32.exe and establishes persistence.

HTTPSpy Installation

Secondary payloads are delivered through multi-stage download chains.

Remote Access Establishment

VS Code tunnels, DWAgent, and malware backdoors provide persistent access.

Technical Analysis

HTTPSpy Remote Access Trojan

HTTPSpy provides full remote administration capabilities including command execution, file upload/download, screenshot capture, process injection, and self-removal functionality.

JSONPing Verification Mechanism

Kimsuky introduced a technique called JSONPing that verifies malware execution status through JSONP requests to a local service running on infected systems before displaying installation prompts.

VS Code Tunnel Abuse

The actor abused Microsoft's legitimate Visual Studio Code Remote Tunneling feature to maintain covert access while reducing reliance on traditional command-and-control infrastructure.

Detection Challenge: Legitimate remote administration technologies such as VS Code Tunnels, DWAgent, and Cloudflare Quick Tunnels can blend with normal enterprise activity, making malicious use difficult to identify.

Malware Arsenal

Malware Function
HTTPSpy Remote Access Trojan
HelloDoor Rust-Based Backdoor
HttpMalice Reconnaissance and Command Execution
HttpTroy Advanced Backdoor
AppleSeed Spyware and Information Theft
HappyDoor Enhanced AppleSeed Variant

Indicators of Compromise (IOCs)

Type Indicator
Executable nos-setup.exe
Executable astx-setup.exe
DLL MemLoader.dll
Script fix-camera.jse
Downloader mTSTCv8.mdxm
Payload engine.dat
DLL spyInster.dll
Loader cacheMon.dat
Critical Alert: Organizations should investigate systems for evidence of regsvr32 abuse, suspicious scheduled tasks, VS Code tunnel usage, unexpected DWAgent installations, and fake security software installers.

MITRE ATT&CK Mapping

Tactic Technique ID
Initial Access Spearphishing Link T1566.002
Execution User Execution T1204
Persistence Scheduled Task T1053.005
Defense Evasion Signed Binary Proxy Execution T1218
Command and Control Application Layer Protocol T1071
Command and Control Remote Access Software T1219
Collection Screen Capture T1113
Credential Access Input Capture T1056

Affected Sectors

Sector Impact
Military Strategic Intelligence Collection
Defense Sensitive Data Theft
Government Credential Harvesting
Energy Operational Reconnaissance
Medical Information Collection
Corporate Long-Term Espionage Access

Mitigation Recommendations

  1. Monitor regsvr32.exe execution activity.
  2. Detect unauthorized VS Code Tunnel usage.
  3. Inspect scheduled tasks for persistence.
  4. Block execution of downloaded JSE files.
  5. Monitor outbound connections to suspicious domains.
  6. Restrict remote management software installations.
  7. Conduct threat hunting for AppleSeed and HTTPSpy artifacts.
  8. Implement phishing-resistant authentication controls.
Recommended Action: Deploy behavioral detection rules focused on social engineering payload chains, remote administration abuse, DLL sideloading, and command execution from unusual user contexts.

References