PULSE NAME
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
WHITE Kimsuky AlienVault 2026-05-29 Modified: 2026-05-29
58
IOCs
HIGH VOLUME
Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
HttpSpy MemLoader calc.exe spyInster.dll spyLoader.dll loadDll.dll
Indicators of Compromise (17 / 58 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a2547836564b0732c6d02a78702da7e6 2026-05-29
FileHash-MD5 a581fdea0970f8a5b6cfec4853c802d7 2026-05-29
FileHash-MD5 a87cd5fd8fe223816005e81e0da70b21 2026-05-29
FileHash-MD5 b4dd4c76d7deef4cf532e240b7f84c9d 2026-05-29
FileHash-MD5 bd8e948a6e61436532cd2ed2b62db3f3 2026-05-29
FileHash-MD5 be31a38bab026f229afd5e3174c363f7 2026-05-29
FileHash-MD5 be978477fe7c179cb9607a6e08a05dff 2026-05-29
FileHash-MD5 bea602695d58cbf25fff058834e36c1d 2026-05-29
FileHash-MD5 c05f074c70a6cacb0e6f05578aab3c9d 2026-05-29
FileHash-MD5 c61a6efe1a169c6c1d8595af3ff0dd74 2026-05-29
FileHash-MD5 c6de1be41dcfbad9cae76c58eae7f5a3 2026-05-29
FileHash-MD5 cc837d2b2af4bd9c1c3faf61cefeb848 2026-05-29
FileHash-MD5 d09c0744273355b6da719fdb62923bed 2026-05-29
FileHash-MD5 dd47c97b44408e0a5ecd8f482fcd0dbc 2026-05-29
FileHash-MD5 ea5f32e1273ec93d43ee09a337fb60e1 2026-05-29
FileHash-MD5 f57a9e973e1cecd6b361467041e464f4 2026-05-29
FileHash-MD5 fcaf03060e34a73fe499b906492d9f13 2026-05-29