The North Korean threat actor Kimsuky has been identified distributing a new backdoor, codenamed HttpTroy, in a targeted spear-phishing campaign against a South Korean victim. The attack leveraged a phishing email containing a ZIP file disguised as a VPN invoice, which, when opened, initiated a multi-stage infection chain involving a dropper, a loader (MemLoad), and the final HttpTroy backdoor. The malware is capable of file transfer, screenshot capture, command execution with elevated privileges, in-memory loading of executables, reverse shell access, process termination, and trace removal. Persistence is established via a scheduled task impersonating the South Korean cybersecurity company AhnLab, and communication with the command-and-control server is conducted over HTTP POST requests.
HttpTroy employs advanced obfuscation techniques, including custom API hashing and string obfuscation using XOR and SIMD instructions, to evade detection and analysis. The campaign highlights the continued evolution of North Korean APT toolsets, with Kimsuky adopting stealthier malware to enhance their cyber-espionage capabilities. Security researchers have emphasized the sophistication of the infection chain and the backdoor's ability to provide attackers with full control over compromised systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
North Korea-linked Lazarus was reported to be using a new variant of the BLINDINGCAN remote access trojan, indicating an upgrade in the group's malware toolkit. The available references present this as a separate development from the Kimsuky HttpTroy activity.
North Korea-linked Kimsuky began a targeted cyberattack campaign against South Korea users using a new HttpTroy backdoor, including lures disguised as a VPN-related invoice. The reporting describes HttpTroy as a stealthy new addition to the group's malware arsenal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.