Analysis of North Korean State-Sponsored Cyber Espionage Operations Targeting South Korean Military and Corporate Organizations
North Korean threat actor Kimsuky conducted multiple cyber espionage campaigns targeting South Korean military, government, defense, medical, machinery, energy, and corporate organizations during March and April 2026.
The campaigns leveraged sophisticated social engineering tactics, fake software installation pages, counterfeit Cisco Webex meeting portals, and legitimate remote access technologies including Visual Studio Code Remote Tunneling, Cloudflare Quick Tunnels, and DWAgent.
Researchers observed the deployment of HTTPSpy, HelloDoor, HttpMalice, HttpTroy, AppleSeed, and HappyDoor malware families for espionage, persistence, reconnaissance, credential theft, and data exfiltration.
Kimsuky
Velvet Chollima
North Korea
Critical
HTTPSpy
Espionage
Kimsuky, also known as Velvet Chollima, is a North Korean state-sponsored advanced persistent threat group known for intelligence gathering operations against government agencies, military organizations, defense contractors, research institutions, and critical infrastructure entities.
The group continues to evolve its tooling and tactics by integrating legitimate remote administration services, open-source software, Rust-based malware, and social engineering campaigns tailored to specific targets.
Initial use of HTTPSpy malware observed.
HelloDoor and HttpMalice malware variants emerge.
Fake security software portals distribute HTTPSpy malware.
Fake Cisco Webex pages used for malware delivery.
Researchers identify expanded malware ecosystem and VS Code Tunnel abuse.
Victims are lured through fake security software installation portals and counterfeit Cisco Webex meeting pages.
Malicious executables launch MemLoader.dll using regsvr32.exe and subsequently execute additional payloads.
Scheduled tasks, VS Code Remote Tunnels, DWAgent, and Cloudflare Quick Tunnels provide long-term access.
Attackers leverage legitimate services, encrypted payloads, anti-analysis checks, and real meeting schedules to evade detection.
HTTPSpy and associated malware families communicate with attacker-controlled infrastructure for command execution and payload retrieval.
Sensitive files, screenshots, keystrokes, certificates, USB device information, and system intelligence are collected and exfiltrated.
| Malware | Purpose |
|---|---|
| HTTPSpy | Remote Access Trojan |
| HelloDoor | Rust-Based Backdoor |
| HttpMalice | Reconnaissance & Data Theft |
| HttpTroy | Remote Access Backdoor |
| AppleSeed | Information Stealer |
| HappyDoor | Advanced Espionage Malware |
| PebbleDash | Malware Framework |
| Tactic | Observed Technique |
|---|---|
| Initial Access | Spearphishing Link |
| Execution | JavaScript & PowerShell |
| Persistence | Scheduled Tasks |
| Persistence | Remote Services |
| Defense Evasion | Masquerading |
| Credential Access | Keylogging |
| Discovery | System Information Discovery |
| Collection | Screen Capture |
| Exfiltration | Data Transfer |
Confidence Level: High
Assessment is based on malware analysis, infrastructure investigation, campaign telemetry, and threat intelligence research published by ENKI and Kaspersky.
Kimsuky continues to demonstrate significant operational maturity through the integration of legitimate remote administration technologies with custom malware frameworks. The abuse of VS Code Remote Tunneling significantly reduces reliance on traditional command-and-control infrastructure and complicates detection efforts.
The combination of social engineering, malware evolution, certificate theft, and stealthy persistence mechanisms highlights Kimsuky's ongoing focus on long-term intelligence collection operations.