#HttpTroy
-Operation SkyCloak targets Russian, Belarusian militaries
-DarkHotel was pretty active this summer
-Kimsuky's new HttpTroy backdoor
-Linux bug exploited by ransomware groups
-GameMaker IDE vulnerability
-New agent session smuggling attack
-Loads of new tools
-Infosec drama, episode 28,311
November 3, 2025 at 9:35 AM
Une nouvelle porte dérobée HttpTroy, déguisée en facture VPN, cible la Corée du Sud 🇰🇷. Le groupe nord-coréen #Kimsuky a lancé une attaque de spear-phishing avec ce malware inédit. #CyberSecurity #IAConversationnelle #InnovationIA https://kntn.ly/7a8181a6
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
New HttpTroy backdoor by Kimsuky targets South Korea using VPN invoice lure, achieving full system control.
thehackernews.com
November 3, 2025 at 5:00 PM
Members of Gen Digital Threat Labs uncover two new DPRK toolsets - Kimsuky’s HttpTroy backdoor and Lazarus’s upgraded BLINDINGCAN remote access tool - and explain how these tools work. www.gendigital.com/blog/insight...
November 3, 2025 at 12:11 PM
ENKI researchers look into a recent Kimsuky campaign that targeted South Korean groupware vendors from 2025 through to early 2026. They identified two new malware strains based on Gomir/HttpTroy, tracked as BirdTroy & DriveTroy. www.enki.co.kr/en/media-cen...
July 22, 2026 at 8:42 AM
신종 Gomir Family를 이용한 Kimsuky의 국내 그룹웨어 개발사 공격 분석
www.enki.co.kr
July 21, 2026 at 2:47 PM
"Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant" published by ENKI. #Kimsuky, #SupplyChain, #Gomir, #HttpTroy https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
www.enki.co.kr
July 21, 2026 at 2:45 PM
Kimsuky used a VPN-invoice ZIP to deliver a 3-stage chain ending in the HttpTroy backdoor. Observables include persistence via scheduled task AhnlabUpdate and C2 load.auraria[.]org. What defenses are you prioritising to catch invoice-style lures?

#CyberSecurity #ThreatIntel #Phishing #Infosec
November 3, 2025 at 3:16 PM
Kimsuky Debuts HTTPTroy Backdoor Against South Korea Users
Kimsuky Debuts HTTPTroy Backdoor Against South Korea Users
www.darkreading.com
November 5, 2025 at 1:57 PM
Kimsuky upgraded PebbleDash and AppleSeed malware with new variants and legitimate tools like VSCode Tunneling and DWAgent to sustain access, steal data, and target sectors across South Korea and beyond. #Kimsuky #SouthKorea #PebbleDash
Kimsuky targets organizations with PebbleDash-based tools
Kimsuky has evolved its PebbleDash and AppleSeed malware clusters with new variants, legitimate tooling like VSCode Tunneling and DWAgent, and infrastructure that hides C2 activity across South Korea and beyond. The campaign used spear-phishing, droppers, and post-exploitation tools to maintain persistence, steal information, and expand access while targeting government, defense, medical, and other sectors. #Kimsuky #PebbleDash #AppleSeed #HelloDoor #httpMalice #httpTroy #HappyDoor #DWAgent #VSCode
www.hendryadrian.com
May 14, 2026 at 12:45 PM
Kimsuky Debuts HTTPTroy Backdoor Against South Korea Users
Kimsuky Debuts HTTPTroy Backdoor Against South Korea Users
The well-known North Korean threat group continues to improve the obfuscation and anti-analysis features of its attack toolchain.
www.darkreading.com
November 5, 2025 at 2:09 AM
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
thehackernews.com
November 3, 2025 at 11:04 AM
HttpTroy backdoor (MEDIUM) deployed by Kimsuky APT via spear-phishing in South Korea. Advanced obfuscation & stealth—defend with EDR, email filtering, and user training. Watch for fake VPN invoices! https://radar.offseq.com/threat/new-httptroy-backdoor-poses-as-vpn-invoice-in-targ-ff3cda7c #OffSe...
November 4, 2025 at 12:01 AM
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea

The North Korea-linked threat actor known as Kimsuky has distributed a previously undocumented backdoor codenamed HttpTroy as part of a likely spear-phishing attack targeting a single victim in Sout…
#hackernews #news
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
The North Korea-linked threat actor known as Kimsuky has distributed a previously undocumented backdoor codenamed HttpTroy as part of a likely spear-phishing attack targeting a single victim in South Korea. Gen Digital, which disclosed details of the activity, did not reveal any details on when the incident occurred, but noted that the phishing email contained a ZIP file ("250908_A_HK이노션
thehackernews.com
November 4, 2025 at 5:30 AM
DPRK's Playbook: Kimsuky's HttpTroy and Lazarus's New BLINDINGCAN Variant https://packetstorm.news/news/view/39359 #news
November 3, 2025 at 4:59 PM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Monday, November 3, 2025
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
New HttpTroy backdoor by Kimsuky targets South Korea using VPN invoice lure, achieving full system control.
thehackernews.com
November 3, 2025 at 12:16 PM
Kimsuky deploys 'HttpTroy' backdoor via fake VPN invoice in targeted South Korean cyberattack. Stay alert! #CyberSecurity #Kimsuky #HttpTroy #Phishing Link: thedailytechfeed.com/kimsuky-depl...
November 4, 2025 at 3:37 PM
North Korean hacker groups Kimsuky and Lazarus deploy advanced backdoor tools, HttpTroy and enhanced BLINDINGCAN, highlighting evolving cyber threats. #CyberSecurity #Kimsuky #LazarusGroup Link: thedailytechfeed.com/north-korean...
November 1, 2025 at 6:00 PM
新たなHttpTroyバックドアがVPN請求書を装い、韓国を標的としたサイバー攻撃を仕掛ける

Kimsukyとして知られる北朝鮮関連の脅威アクターは、韓国の単一の被害者を狙ったと思われるスピアフィッシング攻撃の一環として、これまで文書化されていなかったコード名 HttpTroy のバックドアを配布しました。

活動の詳細を公表したGen Digitalは、事件が発生した時期についての詳細は明かさなかったが、フィッシングメールには、VPN請求書を装ったZIPファイル(「250908_A_HK이노션_SecuwaySSL VPN Manager U100S 100user_견적서.zip」...
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
New HttpTroy backdoor by Kimsuky targets South Korea using VPN invoice lure, achieving full system control.
thehackernews.com
November 5, 2025 at 9:07 PM
KimsukyとLazarusのハッカーがリモートアクセス攻撃のための新しいバックドアツールを展開

北朝鮮の国家支援による脅威アクターは、侵害されたシステムへの永続的なバックドアアクセスを確立するために設計された洗練された新しいマルウェアバリアントの展開により、サイバーオペレーションをエスカレートさせています。

脅威インテリジェンス研究者による最近の調査では、北朝鮮と連携した著名なハッキンググループからの2つの異なるツールセットが明らかになりました。キムスキーが新たに特定したHttpTroyバックドアと、ラザロのBLINDINGCANリモートアクセスツールのアップグレードバージョンです。
Kimsuky and Lazarus Hackers Deploy New Backdoor Tools for Remote Access Attacks
North Korean state-sponsored threat actors have escalated their cyber operations with the deployment of sophisticated new malware variants.
gbhackers.com
November 4, 2025 at 3:43 AM
📌 New HttpTroy Backdoor Deployed by Kimsuky in Targeted South Korean Attack https://www.cyberhub.blog/article/15258-new-httptroy-backdoor-deployed-by-kimsuky-in-targeted-south-korean-attack
New HttpTroy Backdoor Deployed by Kimsuky in Targeted South Korean Attack
The North Korean threat actor group Kimsuky has been identified as distributing a new backdoor named HttpTroy in a spear-phishing attack targeting a single victim in South Korea. The attack involved a phishing email containing a ZIP file titled "250908_A_HK이노션". Notably, HttpTroy is designed to pose as a VPN application, a tactic likely used to evade detection and blend in with legitimate network traffic. While the exact date of the attack remains unspecified, the revelation by Gen Digital highlights the group's continuous evolution of tactics and tools. Kimsuky, also known as APT43, is a well-known North Korean state-sponsored threat actor group that has been active since at least 2012. They are known for targeting South Korean entities, including government agencies, think tanks, and private companies, primarily for espionage purposes. The use of a new backdoor, HttpTroy, which masquerades as a VPN, indicates that the group is continually updating its malware arsenal to evade detection and maintain persistence in targeted networks. The name HttpTroy suggests that the backdoor might use HTTP for command and control (C2) communication, a common tactic to blend malicious traffic with legitimate web traffic. The fact that it poses as a VPN application adds another layer of stealth, as VPN traffic is often encrypted and may bypass certain security controls. The ZIP file name, "250908_A_HK이노션", could indicate a targeted attack against a specific individual or organization, possibly related to HK Inno.N Corporation, a South Korean company. However, without additional context, this remains speculative. The technical implications of this attack are significant. The use of a new backdoor that mimics a VPN application means that existing detection mechanisms may not be effective against HttpTroy. Security teams should update their indicators of compromise (IOCs) and monitor for suspicious HTTP traffic that could indicate C2 communication, especially traffic that appears to be from VPN applications. Additionally, organizations should reinforce their email security measures to detect and block spear-phishing attempts, especially those involving ZIP files from unknown sources. The impact on the cybersecurity landscape is clear: state-sponsored threat actors like Kimsuky are continually evolving their tactics and tools. The use of a VPN-mimicking backdoor highlights the increasing sophistication of these groups in evading detection. This incident underscores the importance of proactive threat hunting and continuous monitoring to detect and respond to advanced persistent threats (APTs). Defenders must stay vigilant and adapt their strategies to counter these evolving threats. From an expert perspective, this attack is a reminder of the persistent threat posed by state-sponsored actors. The use of a VPN-mimicking backdoor is particularly concerning, as it can bypass traditional security controls and remain undetected for extended periods. Organizations, particularly those in South Korea or with ties to the region, should prioritize threat intelligence sharing and implement robust security measures to defend against such targeted attacks. Regular security awareness training for employees can also help mitigate the risk of successful spear-phishing campaigns. In conclusion, the emergence of the HttpTroy backdoor highlights the ongoing evolution of North Korean cyber threats. The use of a VPN-mimicking backdoor underscores the increasing sophistication of these threat actors. Cybersecurity professionals must remain vigilant, update their detection capabilities, and reinforce their defenses against sophisticated phishing attacks and stealthy malware.
www.cyberhub.blog
November 6, 2025 at 9:20 AM
"DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant" published by GenDigital. #BLINDINGCAN, #HttpTroy, #Kimsuky, #Lazarus, #DPRK, #CTI https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis
November 2, 2025 at 1:30 PM