logo

Kimsuky HttpSpy Malware Campaign Exploits Networks via Deceptive Overlays

ID: bb589fd5-5f89-51dc-b01a-d2925ca1042f

STIX ID: report--bb589fd5-5f89-51dc-b01a-d2925ca1042f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-03

Date Updated: 2026-06-07

Author: Ddos

...
...

ENKI Whitehat Threat Research Team reports that the Kimsuky HttpSpy campaign has been revamped into a sophisticated, three-stage espionage operation targeting South Korean military and corporate networks: operators use highly tailored phishing pages (impersonating messaging and Webex services) to deliver a dropper that installs MemLoader.dll/loadDll.dll, employs a novel JSONPing localhost check to verify infections, and ultimately runs a RAM-resident remote access trojan communicating over RC4-encrypted HTTP; investigators observed recurring infrastructure artifacts (default XAMPP certificate and specific ASNs) and note use of Korean-language code/comments likely aided by large language models.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.