TI Mindmap HUB
Threat Intelligence Report

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

📅 May 31, 2026 📰 thehackernews.com 🔍 0 CVE(s) referenced

North Korean threat actor Kimsuky has escalated its cyber operations against South Korean and global targets by deploying new and evolving malware—including HTTPSpy, HelloDoor, and advanced tunneling techniques—leveraging sophisticated social engineering and legitimate tools to maximize infection, persistence, and data exfiltration.

news

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle