securityonline.info 6/3/2026, 8:31:13 AM · external

Kimsuky’s HttpSpy targets Korean military with fake meetings

Kimsuky’s HttpSpy targets Korean military with fake meetings
CyberSIXT Evidence Panel
Primary Source enki.co.kr
Threat Actor

THE Kimsuky HttpSpy malware campaign targets South Korean military and corporate entities, employing advanced social engineering tactics and real-time tracking. Threat actors create deceptive websites mimicking legitimate services to distribute malware. They exploit online meeting platforms like Webex by gathering meeting information from compromised accounts, increasing the authenticity of their phishing attempts. The campaign features a novel JSONPing execution check, allowing real-time monitoring of infections.

The malware operates via a complex three-stage architecture, which includes an installer, a stealth loader, and a remote access trojan module, enabling remote command execution and data manipulation. Defenses against these threats include verifying URLs and practicing good digital hygiene.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline