THREAT INTELLIGENCE REPORT

Kimsuky Deploys HTTPSpy and Expands Arsenal with HelloDoor and VS Code Tunnels

Analysis of North Korean State-Sponsored Cyber Espionage Operations Targeting South Korean Military and Corporate Organizations

Analyst
Rajkumar G
Date
29 May 2026
Classification
Public
Report Type
Threat Intelligence

Executive Summary

North Korean threat actor Kimsuky conducted multiple cyber espionage campaigns targeting South Korean military, government, defense, medical, machinery, energy, and corporate organizations during March and April 2026.

The campaigns leveraged sophisticated social engineering tactics, fake software installation pages, counterfeit Cisco Webex meeting portals, and legitimate remote access technologies including Visual Studio Code Remote Tunneling, Cloudflare Quick Tunnels, and DWAgent.

Researchers observed the deployment of HTTPSpy, HelloDoor, HttpMalice, HttpTroy, AppleSeed, and HappyDoor malware families for espionage, persistence, reconnaissance, credential theft, and data exfiltration.

Key Intelligence Overview

Threat Actor

Kimsuky

Alias

Velvet Chollima

Attribution

North Korea

Severity

Critical

Primary Malware

HTTPSpy

Motivation

Espionage

Threat Actor Attribution

Kimsuky, also known as Velvet Chollima, is a North Korean state-sponsored advanced persistent threat group known for intelligence gathering operations against government agencies, military organizations, defense contractors, research institutions, and critical infrastructure entities.

The group continues to evolve its tooling and tactics by integrating legitimate remote administration services, open-source software, Rust-based malware, and social engineering campaigns tailored to specific targets.

Targeted Sectors

Campaign Timeline

2022

Initial use of HTTPSpy malware observed.

2025

HelloDoor and HttpMalice malware variants emerge.

March 2026

Fake security software portals distribute HTTPSpy malware.

April 2026

Fake Cisco Webex pages used for malware delivery.

May 2026

Researchers identify expanded malware ecosystem and VS Code Tunnel abuse.

Attack Chain Analysis

Initial Access

Victims are lured through fake security software installation portals and counterfeit Cisco Webex meeting pages.

Execution

Malicious executables launch MemLoader.dll using regsvr32.exe and subsequently execute additional payloads.

Persistence

Scheduled tasks, VS Code Remote Tunnels, DWAgent, and Cloudflare Quick Tunnels provide long-term access.

Defense Evasion

Attackers leverage legitimate services, encrypted payloads, anti-analysis checks, and real meeting schedules to evade detection.

Command and Control

HTTPSpy and associated malware families communicate with attacker-controlled infrastructure for command execution and payload retrieval.

Collection & Exfiltration

Sensitive files, screenshots, keystrokes, certificates, USB device information, and system intelligence are collected and exfiltrated.

Observed Malware Families

Malware Purpose
HTTPSpy Remote Access Trojan
HelloDoor Rust-Based Backdoor
HttpMalice Reconnaissance & Data Theft
HttpTroy Remote Access Backdoor
AppleSeed Information Stealer
HappyDoor Advanced Espionage Malware
PebbleDash Malware Framework

MITRE ATT&CK Mapping

Tactic Observed Technique
Initial Access Spearphishing Link
Execution JavaScript & PowerShell
Persistence Scheduled Tasks
Persistence Remote Services
Defense Evasion Masquerading
Credential Access Keylogging
Discovery System Information Discovery
Collection Screen Capture
Exfiltration Data Transfer

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Implement phishing-resistant MFA.
  2. Restrict unauthorized remote access tools.
  3. Monitor VS Code Remote Tunnels.
  4. Disable unnecessary script execution.
  5. Deploy endpoint detection and response solutions.
  6. Monitor certificate store access.
  7. Conduct regular threat hunting exercises.
  8. Provide phishing awareness training.

Confidence Assessment

Confidence Level: High

Assessment is based on malware analysis, infrastructure investigation, campaign telemetry, and threat intelligence research published by ENKI and Kaspersky.

Analyst Assessment

Kimsuky continues to demonstrate significant operational maturity through the integration of legitimate remote administration technologies with custom malware frameworks. The abuse of VS Code Remote Tunneling significantly reduces reliance on traditional command-and-control infrastructure and complicates detection efforts.

The combination of social engineering, malware evolution, certificate theft, and stealthy persistence mechanisms highlights Kimsuky's ongoing focus on long-term intelligence collection operations.

Intelligence Sources

References

Share Report