Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.
AI Analysis
Technical Summary
Kimsuky has deployed advanced malware campaigns against South Korean military and corporate targets using tailored social engineering methods including fake installation pages and Webex meeting spoofing. The threat actor introduced JSONPing, a technique that uses JSONP queries to localhost servers to confirm payload execution in real time. The new HttpSpy variant features a three-stage execution chain with RC4 encryption, replacing the prior single-binary design. Attribution is confirmed through multiple technical indicators such as code pattern overlaps, encryption key reuse, XAMPP certificate fingerprints, and ASN preferences consistent with historical Kimsuky activity. These campaigns are ongoing through April 2026 and focus on South Korean entities.
Potential Impact
The campaigns enable Kimsuky to conduct targeted espionage against South Korean military and corporate organizations by deploying advanced malware with real-time payload verification and sophisticated execution chains. The use of social engineering and Webex spoofing increases the likelihood of successful victim compromise. The new HttpSpy variant's multi-stage execution and encryption techniques enhance stealth and persistence. There are no reports of widespread exploitation beyond these targeted campaigns.
Mitigation Recommendations
No official patches or fixes are available as this is a malware campaign rather than a software vulnerability. Organizations should be aware of the social engineering tactics described, including fake security software pages and spoofed Webex meeting invitations. Monitoring for indicators of compromise related to Kimsuky, such as the use of JSONPing and the new HttpSpy variant, is recommended. Since the threat targets South Korean entities specifically, heightened vigilance in these sectors is advised. Patch status is not applicable; follow vendor and threat intelligence updates for any new mitigation guidance.
Affected Countries
South Korea
Indicators of Compromise
- domain: load.serverpit.com
- hash: c089457d5f4b22313b927bb36a320f8d7a1ddb6d5b82293dc2374dcfd4b1b8b2
- domain: load.erasecloud.n-e.kr
- hash: 784d9273c75e983f2b4730d1f2198cc44e9599709f4a5519a2bd3049095dc9d5
- hash: a2547836564b0732c6d02a78702da7e6
- hash: a581fdea0970f8a5b6cfec4853c802d7
- hash: a87cd5fd8fe223816005e81e0da70b21
- hash: b4dd4c76d7deef4cf532e240b7f84c9d
- hash: bd8e948a6e61436532cd2ed2b62db3f3
- hash: be31a38bab026f229afd5e3174c363f7
- hash: be978477fe7c179cb9607a6e08a05dff
- hash: bea602695d58cbf25fff058834e36c1d
- hash: c05f074c70a6cacb0e6f05578aab3c9d
- hash: c61a6efe1a169c6c1d8595af3ff0dd74
- hash: c6de1be41dcfbad9cae76c58eae7f5a3
- hash: cc837d2b2af4bd9c1c3faf61cefeb848
- hash: d09c0744273355b6da719fdb62923bed
- hash: dd47c97b44408e0a5ecd8f482fcd0dbc
- hash: ea5f32e1273ec93d43ee09a337fb60e1
- hash: f57a9e973e1cecd6b361467041e464f4
- hash: fcaf03060e34a73fe499b906492d9f13
- hash: 364cc871e66afe65e1845205105c3f53f34afc01
- hash: b44e800436b2892f7c8f9fbd93e5e17a2e1fde04
- hash: c124f019ddaef2606a7394b0b9bf7ae1a05ecda4
- hash: ca42cba2782a0b6952dd0425fa08cbd4de65f77fcc00e965ee97c39bea42eb18
- ip: 157.250.202.123
- ip: 27.102.113.106
- url: http://appview.imagetemplate.com/gateless_icon
- url: http://bigfile.jaycloudlab.com/download.php?id=745896
- url: http://download.birdriver.org/download.php?id=393156
- url: http://hdrgdrfes.chickenkiller.com/index.php
- url: http://load.erasecloud.n-e.kr/login.php
- url: http://load.serverpit.com/fwrite.php
- url: http://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless
- url: http://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=gateless
- url: http://www.ibizplus.n-e.kr/download.php?id=30382119
- url: http://www.ibizplus.n-e.kr/download.php?id=30382120
- url: http://www.ibizplus.n-e.kr/download.php?id=30382121
- url: https://appview.imagetemplate.com/babymetalsave_icon
- url: https://appview.imagetemplate.com/gateless_icon
- url: https://bigfile.crabdance.com/recaptcha.html
- url: https://conference.birdriver.org/
- url: https://download.birdriver.org/download.php?id=393156
- url: https://download.birdriver.org/download.php?id=425623
- url: https://load.erasecloud.n-e.kr/login.php
- url: https://load.serverpit.com/fwrite.php
- url: https://pipeline.embeddedonline.org/check.php?x-csrf-token=babymetalsave
- url: https://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless
- url: https://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=babymetalsave
- url: https://www.ibizplus.n-e.kr/install.html
- domain: appview.imagetemplate.com
- domain: bigfile.crabdance.com
- domain: bigfile.jaycloudlab.com
- domain: conference.birdriver.org
- domain: download.birdriver.org
- domain: hdrgdrfes.chickenkiller.com
- domain: pipeline.embeddedonline.org
- domain: www.ibizplus.n-e.kr
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
Description
Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kimsuky has deployed advanced malware campaigns against South Korean military and corporate targets using tailored social engineering methods including fake installation pages and Webex meeting spoofing. The threat actor introduced JSONPing, a technique that uses JSONP queries to localhost servers to confirm payload execution in real time. The new HttpSpy variant features a three-stage execution chain with RC4 encryption, replacing the prior single-binary design. Attribution is confirmed through multiple technical indicators such as code pattern overlaps, encryption key reuse, XAMPP certificate fingerprints, and ASN preferences consistent with historical Kimsuky activity. These campaigns are ongoing through April 2026 and focus on South Korean entities.
Potential Impact
The campaigns enable Kimsuky to conduct targeted espionage against South Korean military and corporate organizations by deploying advanced malware with real-time payload verification and sophisticated execution chains. The use of social engineering and Webex spoofing increases the likelihood of successful victim compromise. The new HttpSpy variant's multi-stage execution and encryption techniques enhance stealth and persistence. There are no reports of widespread exploitation beyond these targeted campaigns.
Mitigation Recommendations
No official patches or fixes are available as this is a malware campaign rather than a software vulnerability. Organizations should be aware of the social engineering tactics described, including fake security software pages and spoofed Webex meeting invitations. Monitoring for indicators of compromise related to Kimsuky, such as the use of JSONPing and the new HttpSpy variant, is recommended. Since the threat targets South Korean entities specifically, heightened vigilance in these sectors is advised. Patch status is not applicable; follow vendor and threat intelligence updates for any new mitigation guidance.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant"]
- Adversary
- Kimsuky
- Pulse Id
- 6a19766cc7caf96e27eae35e
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainload.serverpit.com | — | |
domainload.erasecloud.n-e.kr | — | |
domainappview.imagetemplate.com | — | |
domainbigfile.crabdance.com | — | |
domainbigfile.jaycloudlab.com | — | |
domainconference.birdriver.org | — | |
domaindownload.birdriver.org | — | |
domainhdrgdrfes.chickenkiller.com | — | |
domainpipeline.embeddedonline.org | — | |
domainwww.ibizplus.n-e.kr | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashc089457d5f4b22313b927bb36a320f8d7a1ddb6d5b82293dc2374dcfd4b1b8b2 | — | |
hash784d9273c75e983f2b4730d1f2198cc44e9599709f4a5519a2bd3049095dc9d5 | — | |
hasha2547836564b0732c6d02a78702da7e6 | — | |
hasha581fdea0970f8a5b6cfec4853c802d7 | — | |
hasha87cd5fd8fe223816005e81e0da70b21 | — | |
hashb4dd4c76d7deef4cf532e240b7f84c9d | — | |
hashbd8e948a6e61436532cd2ed2b62db3f3 | — | |
hashbe31a38bab026f229afd5e3174c363f7 | — | |
hashbe978477fe7c179cb9607a6e08a05dff | — | |
hashbea602695d58cbf25fff058834e36c1d | — | |
hashc05f074c70a6cacb0e6f05578aab3c9d | — | |
hashc61a6efe1a169c6c1d8595af3ff0dd74 | — | |
hashc6de1be41dcfbad9cae76c58eae7f5a3 | — | |
hashcc837d2b2af4bd9c1c3faf61cefeb848 | — | |
hashd09c0744273355b6da719fdb62923bed | — | |
hashdd47c97b44408e0a5ecd8f482fcd0dbc | — | |
hashea5f32e1273ec93d43ee09a337fb60e1 | — | |
hashf57a9e973e1cecd6b361467041e464f4 | — | |
hashfcaf03060e34a73fe499b906492d9f13 | — | |
hash364cc871e66afe65e1845205105c3f53f34afc01 | — | |
hashb44e800436b2892f7c8f9fbd93e5e17a2e1fde04 | — | |
hashc124f019ddaef2606a7394b0b9bf7ae1a05ecda4 | — | |
hashca42cba2782a0b6952dd0425fa08cbd4de65f77fcc00e965ee97c39bea42eb18 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip157.250.202.123 | — | |
ip27.102.113.106 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://appview.imagetemplate.com/gateless_icon | — | |
urlhttp://bigfile.jaycloudlab.com/download.php?id=745896 | — | |
urlhttp://download.birdriver.org/download.php?id=393156 | — | |
urlhttp://hdrgdrfes.chickenkiller.com/index.php | — | |
urlhttp://load.erasecloud.n-e.kr/login.php | — | |
urlhttp://load.serverpit.com/fwrite.php | — | |
urlhttp://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless | — | |
urlhttp://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=gateless | — | |
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382119 | — | |
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382120 | — | |
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382121 | — | |
urlhttps://appview.imagetemplate.com/babymetalsave_icon | — | |
urlhttps://appview.imagetemplate.com/gateless_icon | — | |
urlhttps://bigfile.crabdance.com/recaptcha.html | — | |
urlhttps://conference.birdriver.org/ | — | |
urlhttps://download.birdriver.org/download.php?id=393156 | — | |
urlhttps://download.birdriver.org/download.php?id=425623 | — | |
urlhttps://load.erasecloud.n-e.kr/login.php | — | |
urlhttps://load.serverpit.com/fwrite.php | — | |
urlhttps://pipeline.embeddedonline.org/check.php?x-csrf-token=babymetalsave | — | |
urlhttps://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless | — | |
urlhttps://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=babymetalsave | — | |
urlhttps://www.ibizplus.n-e.kr/install.html | — |
Threat ID: 6a198b22e29bf47b50e58d61
Added to database: 05/29/2026, 12:48:34 UTC
Last enriched: 06/28/2026, 20:52:33 UTC
Last updated: 07/20/2026, 22:01:19 UTC
Views: 603
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.