Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant

0
Medium
Published: 05/29/2026 (05/29/2026, 11:20:12 UTC)
Source: AlienVault OTX General

Description

Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/28/2026, 20:52:33 UTC

Technical Analysis

Kimsuky has deployed advanced malware campaigns against South Korean military and corporate targets using tailored social engineering methods including fake installation pages and Webex meeting spoofing. The threat actor introduced JSONPing, a technique that uses JSONP queries to localhost servers to confirm payload execution in real time. The new HttpSpy variant features a three-stage execution chain with RC4 encryption, replacing the prior single-binary design. Attribution is confirmed through multiple technical indicators such as code pattern overlaps, encryption key reuse, XAMPP certificate fingerprints, and ASN preferences consistent with historical Kimsuky activity. These campaigns are ongoing through April 2026 and focus on South Korean entities.

Potential Impact

The campaigns enable Kimsuky to conduct targeted espionage against South Korean military and corporate organizations by deploying advanced malware with real-time payload verification and sophisticated execution chains. The use of social engineering and Webex spoofing increases the likelihood of successful victim compromise. The new HttpSpy variant's multi-stage execution and encryption techniques enhance stealth and persistence. There are no reports of widespread exploitation beyond these targeted campaigns.

Mitigation Recommendations

No official patches or fixes are available as this is a malware campaign rather than a software vulnerability. Organizations should be aware of the social engineering tactics described, including fake security software pages and spoofed Webex meeting invitations. Monitoring for indicators of compromise related to Kimsuky, such as the use of JSONPing and the new HttpSpy variant, is recommended. Since the threat targets South Korean entities specifically, heightened vigilance in these sectors is advised. Patch status is not applicable; follow vendor and threat intelligence updates for any new mitigation guidance.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant"]
Adversary
Kimsuky
Pulse Id
6a19766cc7caf96e27eae35e
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainload.serverpit.com
domainload.erasecloud.n-e.kr
domainappview.imagetemplate.com
domainbigfile.crabdance.com
domainbigfile.jaycloudlab.com
domainconference.birdriver.org
domaindownload.birdriver.org
domainhdrgdrfes.chickenkiller.com
domainpipeline.embeddedonline.org
domainwww.ibizplus.n-e.kr

Hash

ValueDescriptionCopy
hashc089457d5f4b22313b927bb36a320f8d7a1ddb6d5b82293dc2374dcfd4b1b8b2
hash784d9273c75e983f2b4730d1f2198cc44e9599709f4a5519a2bd3049095dc9d5
hasha2547836564b0732c6d02a78702da7e6
hasha581fdea0970f8a5b6cfec4853c802d7
hasha87cd5fd8fe223816005e81e0da70b21
hashb4dd4c76d7deef4cf532e240b7f84c9d
hashbd8e948a6e61436532cd2ed2b62db3f3
hashbe31a38bab026f229afd5e3174c363f7
hashbe978477fe7c179cb9607a6e08a05dff
hashbea602695d58cbf25fff058834e36c1d
hashc05f074c70a6cacb0e6f05578aab3c9d
hashc61a6efe1a169c6c1d8595af3ff0dd74
hashc6de1be41dcfbad9cae76c58eae7f5a3
hashcc837d2b2af4bd9c1c3faf61cefeb848
hashd09c0744273355b6da719fdb62923bed
hashdd47c97b44408e0a5ecd8f482fcd0dbc
hashea5f32e1273ec93d43ee09a337fb60e1
hashf57a9e973e1cecd6b361467041e464f4
hashfcaf03060e34a73fe499b906492d9f13
hash364cc871e66afe65e1845205105c3f53f34afc01
hashb44e800436b2892f7c8f9fbd93e5e17a2e1fde04
hashc124f019ddaef2606a7394b0b9bf7ae1a05ecda4
hashca42cba2782a0b6952dd0425fa08cbd4de65f77fcc00e965ee97c39bea42eb18

Ip

ValueDescriptionCopy
ip157.250.202.123
ip27.102.113.106

Url

ValueDescriptionCopy
urlhttp://appview.imagetemplate.com/gateless_icon
urlhttp://bigfile.jaycloudlab.com/download.php?id=745896
urlhttp://download.birdriver.org/download.php?id=393156
urlhttp://hdrgdrfes.chickenkiller.com/index.php
urlhttp://load.erasecloud.n-e.kr/login.php
urlhttp://load.serverpit.com/fwrite.php
urlhttp://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless
urlhttp://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=gateless
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382119
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382120
urlhttp://www.ibizplus.n-e.kr/download.php?id=30382121
urlhttps://appview.imagetemplate.com/babymetalsave_icon
urlhttps://appview.imagetemplate.com/gateless_icon
urlhttps://bigfile.crabdance.com/recaptcha.html
urlhttps://conference.birdriver.org/
urlhttps://download.birdriver.org/download.php?id=393156
urlhttps://download.birdriver.org/download.php?id=425623
urlhttps://load.erasecloud.n-e.kr/login.php
urlhttps://load.serverpit.com/fwrite.php
urlhttps://pipeline.embeddedonline.org/check.php?x-csrf-token=babymetalsave
urlhttps://pipeline.embeddedonline.org/check.php?x-csrf-token=gateless
urlhttps://pipeline.embeddedonline.org/download3.php?sessid=54126&user-token=babymetalsave
urlhttps://www.ibizplus.n-e.kr/install.html

Threat ID: 6a198b22e29bf47b50e58d61

Added to database: 05/29/2026, 12:48:34 UTC

Last enriched: 06/28/2026, 20:52:33 UTC

Last updated: 07/20/2026, 22:01:19 UTC

Views: 603

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses