A simple click on a fake installer or Webex fix can now turn into a long-lived espionage channel. Kimsuky is using those trusted pages to get code running, then leaving persistence behind so the foothold survives after the original lure disappears.
ENKI ties March-April 2026 activity to fake security software pages and a bogus Webex camera prompt that delivered HTTPSpy variants. The same campaign adds HelloDoor and VS Code tunneling, which gives the actor a quieter path for remote access and selective exfiltration instead of a one-off payload drop.
The shift matters because a user-click incident no longer ends when the initial file is removed. For South Korean military and corporate targets, the risk is a managed access path that can keep pulling data long after the first lure is contained.