Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets

The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.

ThreatVectr Newsdesk· 2 min read
Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets
Share

North Korea's Kimsuky has spent March and April 2026 working through a fresh roster of social-engineering lures aimed at South Korean military units and private-sector targets, according to incident telemetry reviewed by researchers tracking the group.

The campaign is notable less for novel exploitation than for tooling. Kimsuky — also tracked as Velvet Chollima — has paired older tradecraft with two new implants, HTTPSpy and HelloDoor, and is abusing Visual Studio Code's remote tunnel feature for stealthy command-and-control.

The lures are mundane on purpose. Operators stood up spoofed antivirus installation pages and a counterfeit Webex meeting page designed to harvest credentials and deliver first-stage payloads. Both leaned on Korean-language branding consistent with the targeted sectors.

HTTPSpy functions as a reconnaissance and surveillance tool. It collects host metadata, exfiltrates documents, and beacons over HTTPS to attacker infrastructure. HelloDoor is a backdoor with file transfer, shell execution, and persistence routines. The two appear to be deployed in sequence, with HTTPSpy used to triage victims before HelloDoor lands on systems judged worth the follow-through.

The VS Code tunnel abuse is the more interesting tradecraft note. By registering victim machines to a Microsoft-signed tunnel service, Kimsuky operators get interactive access that rides legitimate developer infrastructure and evades a lot of egress filtering. Microsoft has previously flagged similar abuse by other state actors, though no advisory has yet been published for this specific cluster.

Targeting in the observed intrusions skewed toward defense contractors, think tanks working on inter-Korean policy, and IT staff at companies in the supply chain for South Korean military procurement. That aligns with Kimsuky's long-running intelligence brief.

No CVEs are in play. This is credential theft and consent abuse, not exploitation. South Korea's KISA is the relevant national CERT for affected organisations, and the Personal Information Protection Commission (PIPC) holds jurisdiction over any resulting personal-data exposure under PIPA.

What affected users and defenders should do:

  • Audit Visual Studio Code tunnel registrations across managed endpoints. If your developers aren't using code tunnel, the binary's outbound calls to *.tunnels.api.visualstudio.com are worth alerting on.
  • Treat any unsolicited Webex invite or antivirus update page reached via email link as hostile until proven otherwise. Verify installers against vendor hashes, not the page that served them.
  • Reset credentials for any account that touched a spoofed login page in the window, and revoke active session tokens rather than relying on password rotation alone.
  • If you're a defense supplier or policy organisation in South Korea, assume you're in scope and hunt for HTTPSpy indicators retroactively to early March.

Kimsuky isn't getting more sophisticated. It's getting more patient, and more comfortable hiding inside tools defenders already trust.

© 2026 Threat Vectr