Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

2026-05-29T07:24:09Z5629211b94e4d3df7ec6a0858c42ddfc3274fe77965811ad398a6e4841ea2c47
CERT‑InCobalt StrikeDLL sideloadingFortiClient EMSGhost CMSGiteaGlassWormGogsJINX-0164KimsukyKnowledgeDeliverLazarusMuddyWaterNimbus ManticoreRemote code executionSQL injectionSharePointVS Code tunnelscoordinated disclosurecredential‑stealernpmpatchingsocial engineeringstate-sponsoredsupply-chain

What happened

A cluster of high-impact incidents and disclosures across late May 2026: multiple state-linked campaigns (Kimsuky, Lazarus, MuddyWater, Nimbus Manticore) and novel criminal groups (JINX-0164) are deploying custom malware and social‑engineering lures (HTTPSpy, HelloDoor, RemotePE, DPAPILoader/RemotePELoader, Grandoreiro, BTMOB) and abusing developer and endpoint infrastructure. Active exploitation of critical flaws includes a Gogs authenticated RCE (CVSS 9.4, no CVE assigned), Ghost CMS CVE-2026-26980 (SQLi, CVSS 9.4) used to hijack sites, and ongoing exploitation of a FortiClient EMS flaw to配送

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5629211b94e4d3df7ec6a0858c42ddfc3274fe77965811ad398a6e4841ea2c47
Enrichment time
2026-05-29T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.