HTTPSpy is a Windows remote access trojan associated with the DPRK-linked threat actor Kimsuky. It has been used in espionage-oriented campaigns targeting South Korean military, government, defense, healthcare, and corporate organizations, and has also been reported in operations affecting defense-related entities outside South Korea. The malware is commonly delivered through tailored social-engineering lures, including counterfeit Cisco Webex meeting pages built around real meeting schedules and fake security-software installation portals impersonating trusted Korean services and institutions.
Recent HTTPSpy activity shows a staged infection chain rather than a single standalone implant. Campaigns have used an obfuscated script or installer to launch an intermediate downloader or loader, which performs anti-analysis checks for virtualized and instrumented environments, retrieves additional encrypted components, and ultimately loads the core HTTPSpy module in memory. Observed variants establish persistence through Windows Run keys or services and use HTTP or HTTPS for command-and-control communications. Traffic is protected with RC4 encryption and Base64 encoding, and the malware uses structured web requests to exchange tasking and results with its operators.
HTTPSpy is a full-featured RAT designed for post-compromise control and intelligence collection. Documented capabilities include executing shell commands, launching hidden processes, uploading and downloading files, capturing screenshots, updating configuration, timestomping, self-removal, and injecting DLLs into selected processes. Some campaigns also used adjacent web-based logic to verify whether the malware was already active on the victim host before prompting further execution, improving delivery efficiency. The malware’s tradecraft, infrastructure overlaps, and recurring use in Kimsuky social-engineering operations make it a notable component of that actor’s espionage toolkit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Summary ... Social engineering (Job offer) Backdoor (httpSpy, PebbleDash) ... Attribution of this campaign
Summary ... Social engineering (Job offer) Backdoor (httpSpy, PebbleDash) ... Attribution of this campaign
28 distinct techniques documented for this family, organized by ATT&CK tactic.
For all other commands, it executes them via cmd.exe /c , redirects standard output to a temporary file matching %TEMP%\NK[0-9a-fA-F]+\.tmp , collects the output, and sends it to the C&C server.
fix-camera.jse 는 base64 인코딩 상태로 포함된 악성코드와 미끼 html 파일을 각각 ... 생성하고 실행한다.
jse 스크립트는 base64 인코딩 된 데이터를 쓰레기 변수에 할당하거나, 문자열을 슬라이싱 해 "+" 연산으로 조합하는 등 여러 난독화 방식이 적용되어 있다.
engine.dat decrypts an embedded RC4-encrypted payload and drops it to C:\Users\Public\cacheMon.dat . It then RC4-decrypts the configuration data and appends it to cacheMon.dat as a DATA_CONF alternate data stream (ADS).
| DLL | Admin | ChromeUpdate | Uses regsvr32 + highest privileges | ... | EXE | User | EdgeUpdate | Direct execution
In its main loop, the malware loads the C&C server URL ... and receives remote commands via HTTP POST.
If a proxy address is set at offset +0x410 (1040) in the configuration file, communication is routed through that proxy, with 2[.]2[.]2[.]2 used as the proxy bypass address.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan installed through a multi-stage chain. It communicates with a C2 over HTTP POST, supports shell command execution, file upload/download, screenshot capture, configuration updates, proxy use, self-deletion, and remote DLL injection.
Fake Webex meeting pages deliver a multi-stage loader chain that ultimately installs a HttpSpy variant. The RAT communicates with C2 over HTTP POST, supports command execution, file download/upload, screenshot capture, configuration updates, proxy use, timestomping, self-delete, and remote DLL injection, and persists via a Run key invoking regsvr32 on cacheMon.dat.
A Kimsuky-associated remote access trojan used in cyber espionage campaigns. The described variant uses a three-stage chain consisting of an installer, a stealth loader, and the core RAT module. It performs environment checks, downloads the primary implant, executes shell commands, captures screenshots, manipulates local documents remotely, and communicates over HTTP POST with RC4-encrypted data transmission.
Remote access trojan used by Kimsuky, delivered via spoofed security software installers and fake Webex pages to provide covert access to victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.