Analysis of North Korean threat actor Kimsuky's latest cyber espionage campaign targeting South Korean military, government, defense, corporate, and critical infrastructure sectors using social engineering, HTTPSpy RAT, HelloDoor, AppleSeed malware, and legitimate remote access technologies.
Kimsuky, also tracked as Velvet Chollima, conducted targeted cyber espionage operations against South Korean military and enterprise organizations throughout March and April 2026. The campaign leveraged fake software installers, counterfeit Cisco Webex meeting pages, social engineering, and multiple malware families to compromise victims and establish long-term persistence.
The threat actor deployed HTTPSpy remote access trojans, HelloDoor backdoors, AppleSeed spyware, HttpMalice, HttpTroy, and abused legitimate remote administration services such as Microsoft Visual Studio Code Remote Tunneling, Cloudflare Quick Tunnels, and DWAgent to evade detection and maintain access.
Critical
Kimsuky
Espionage
South Korea
6+
VS Code Tunnel
| Category | Details |
|---|---|
| Threat Group | Kimsuky (Velvet Chollima) |
| Attribution | North Korean State-Sponsored |
| Primary Objective | Cyber Espionage |
| Victim Sectors | Military, Government, Defense, Energy, Medical, Corporate |
| Target Geography | South Korea, Germany, Brazil |
| Operational Period | March-April 2026 |
Victims receive links to fake security software pages and counterfeit Webex meeting portals.
Victims download fake security tools disguised as nProtect Online Security and AhnLab Safe Transaction.
MemLoader.dll is executed through regsvr32.exe and establishes persistence.
Secondary payloads are delivered through multi-stage download chains.
VS Code tunnels, DWAgent, and malware backdoors provide persistent access.
HTTPSpy provides full remote administration capabilities including command execution, file upload/download, screenshot capture, process injection, and self-removal functionality.
Kimsuky introduced a technique called JSONPing that verifies malware execution status through JSONP requests to a local service running on infected systems before displaying installation prompts.
The actor abused Microsoft's legitimate Visual Studio Code Remote Tunneling feature to maintain covert access while reducing reliance on traditional command-and-control infrastructure.
| Malware | Function |
|---|---|
| HTTPSpy | Remote Access Trojan |
| HelloDoor | Rust-Based Backdoor |
| HttpMalice | Reconnaissance and Command Execution |
| HttpTroy | Advanced Backdoor |
| AppleSeed | Spyware and Information Theft |
| HappyDoor | Enhanced AppleSeed Variant |
| Type | Indicator |
|---|---|
| Executable | nos-setup.exe |
| Executable | astx-setup.exe |
| DLL | MemLoader.dll |
| Script | fix-camera.jse |
| Downloader | mTSTCv8.mdxm |
| Payload | engine.dat |
| DLL | spyInster.dll |
| Loader | cacheMon.dat |
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Spearphishing Link | T1566.002 |
| Execution | User Execution | T1204 |
| Persistence | Scheduled Task | T1053.005 |
| Defense Evasion | Signed Binary Proxy Execution | T1218 |
| Command and Control | Application Layer Protocol | T1071 |
| Command and Control | Remote Access Software | T1219 |
| Collection | Screen Capture | T1113 |
| Credential Access | Input Capture | T1056 |
| Sector | Impact |
|---|---|
| Military | Strategic Intelligence Collection |
| Defense | Sensitive Data Theft |
| Government | Credential Harvesting |
| Energy | Operational Reconnaissance |
| Medical | Information Collection |
| Corporate | Long-Term Espionage Access |