Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종

2026-05-27 ENKI Analysis of Kimsuky's Advanced Attack Techniques: JSONPing, Webex Impersonation, and a New HttpSpy Variant

https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant

Thumbnail for Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종

ENKI Whitehat identified Kimsuky malware delivery activity through April 2026 against South Korean military and enterprise-related targets. The campaigns used tailored lures, including fake domestic security software installation pages and a fake Webex meeting page built around a real meeting schedule. ENKI documented JSONPing, a JSONP-based localhost callback technique used by distribution pages to check whether malware is already running on the victim host. In the Webex chain, the final payload was a new HttpSpy variant using a three-stage installer, loader, and main module flow, with links to Kimsuky supported by reused RC4 keys, infrastructure, code patterns, export names, and certificate reuse.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN appview.imagetemplate.com 2026-05-27 2026-05-27
HASH b18118f61a4dcb51df5e189c40dd3280 2026-05-27 2026-05-27
HASH 1efaf988fded55cd3b974c66f4ca8f7e 2026-05-27 2026-05-27
HASH bd8e948a6e61436532cd2ed2b62db3f3 2026-05-27 2026-05-27
HASH 39e091e981d9daab56e680927508bd1f 2026-05-27 2026-05-27
HASH 3369b911cf3706a2660d2af9b3c35f9a 2026-05-27 2026-05-27
HASH f57a9e973e1cecd6b361467041e464f4 2026-05-27 2026-05-27
HASH dd47c97b44408e0a5ecd8f482fcd0dbc 2026-05-27 2026-05-27
HASH fcaf03060e34a73fe499b906492d9f13 2026-05-27 2026-05-27
HASH d09c0744273355b6da719fdb62923bed 2026-05-27 2026-05-27
HASH 8833a270ddef0f464d5916958b6778e6 2026-05-27 2026-05-27
HASH be978477fe7c179cb9607a6e08a05dff 2026-05-27 2026-05-27
HASH 9df5ca76ac085b89c1ddcb3963e9fe97 2026-05-27 2026-05-27
HASH a581fdea0970f8a5b6cfec4853c802d7 2026-05-27 2026-05-27
HASH 50f619aaba1d28882022ced135b13a07 2026-05-27 2026-05-27
HASH c6de1be41dcfbad9cae76c58eae7f5a3 2026-05-27 2026-05-27
HASH c61a6efe1a169c6c1d8595af3ff0dd74 2026-05-27 2026-05-27
HASH be31a38bab026f229afd5e3174c363f7 2026-05-27 2026-05-27
HASH b4dd4c76d7deef4cf532e240b7f84c9d 2026-05-27 2026-05-27
HASH 6d2dfd7ca77530afec000a197d6b8677 2026-05-27 2026-05-27
HASH 0d07fb6d1a3736ea543ab8364115e435 2026-05-27 2026-05-27
HASH ea5f32e1273ec93d43ee09a337fb60e1 2026-05-27 2026-05-27
HASH bea602695d58cbf25fff058834e36c1d 2026-05-27 2026-05-27
HASH 97b4c2e67e5e18b70949690a69820c2a 2026-05-27 2026-05-27
HASH cc837d2b2af4bd9c1c3faf61cefeb848 2026-05-27 2026-05-27
HASH 00f957b7dafd8d210e717041add02eab 2026-05-27 2026-05-27
HASH 4a476abcf741323b367eda0ec49f8c38 2026-05-27 2026-05-27
IPv4 27.102.113.106 2026-05-27 2026-05-27
IPv4 157.250.202.123 2026-05-27 2026-05-27
DOMAIN bigfile.jaycloudlab.com 2026-05-27 2026-05-27
URL https://bigfile.jaycloudlab.com… 2026-05-27 2026-05-27
DOMAIN load.erasecloud.n-e.kr 2026-05-27 2026-05-27
URL https://load.erasecloud.n-e.kr/… 2026-05-27 2026-05-27
URL https://pipeline.embeddedonline… 2026-05-27 2026-05-27
DOMAIN pipeline.embeddedonline.org 2026-05-27 2026-05-27
URL https://pipeline.embeddedonline… 2026-05-27 2026-05-27
DOMAIN hdrgdrfes.chickenkiller.com 2026-05-27 2026-05-27
URL http://hdrgdrfes.chickenkiller.… 2026-05-27 2026-05-27
URL https://download.birdriver.org/… 2026-05-27 2026-05-27
DOMAIN download.birdriver.org 2026-05-27 2026-05-27
URL https://download.birdriver.org/… 2026-05-27 2026-05-27
DOMAIN conference.birdriver.org 2026-05-27 2026-05-27
URL https://conference.birdriver.or… 2026-05-27 2026-05-27
DOMAIN load.serverpit.com 2026-05-27 2026-05-27
URL https://load.serverpit.com/fwri… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/dow… 2026-05-27 2026-05-27
DOMAIN ibizplus.n-e.kr 2026-05-27 2026-05-27
URL https://www.ibizplus.n-e.kr/ins… 2026-05-27 2026-05-27

Related Actors

Related Reports

2026-04-17 • 45% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, T1140, T1041
« Back