Threats & Adversaries · APT / Espionage

Kimsuky Turns Fake Fixes Into Persistent Access

A simple click on a fake installer or Webex fix can now turn into a long-lived espionage channel. Kimsuky is using those trusted pages to get code running, then leaving persistence behind so the foothold survives after the original lure disappears.

ENKI ties March-April 2026 activity to fake security software pages and a bogus Webex camera prompt that delivered HTTPSpy variants. The same campaign adds HelloDoor and VS Code tunneling, which gives the actor a quieter path for remote access and selective exfiltration instead of a one-off payload drop.

The shift matters because a user-click incident no longer ends when the initial file is removed. For South Korean military and corporate targets, the risk is a managed access path that can keep pulling data long after the first lure is contained.

1 source · May 29

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-05-30

Every edition of this story: Kimsuky Turns Fake Fixes Into Persistent Access

More from today