Threats · 108 days ago
A simple click on a fake installer or Webex fix can now turn into a long-lived espionage channel. Kimsuky is using those trusted pages to get code running, then leaving persistence behind so the foothold survives after the original lure disappears.
ENKI ties March-April 2026 activity to fake security software pages and a bogus Webex camera prompt that delivered HTTPSpy variants. The same campaign adds HelloDoor and VS Code tunneling, which gives the actor a quieter path for remote access and selective exfiltration instead of a one-off payload drop.
The shift matters because a user-click incident no longer ends when the initial file is removed. For South Korean military and corporate targets, the risk is a managed access path that can keep pulling data long after the first lure is contained.
1 source covering this story
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
Kimsuky used fake security tools and Webex pages in March-April 2026 to deploy HTTPSpy, enabling persistent espionage and data theft.
Part of the PlainSec briefing for 2026-05-30