Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
2026-05-29T07:24:09Z•5629211b94e4d3df7ec6a0858c42ddfc3274fe77965811ad398a6e4841ea2c47
CERT‑InCobalt StrikeDLL sideloadingFortiClient EMSGhost CMSGiteaGlassWormGogsJINX-0164KimsukyKnowledgeDeliverLazarusMuddyWaterNimbus ManticoreRemote code executionSQL injectionSharePointVS Code tunnelscoordinated disclosurecredential‑stealernpmpatchingsocial engineeringstate-sponsoredsupply-chain
What happened
A cluster of high-impact incidents and disclosures across late May 2026: multiple state-linked campaigns (Kimsuky, Lazarus, MuddyWater, Nimbus Manticore) and novel criminal groups (JINX-0164) are deploying custom malware and social‑engineering lures (HTTPSpy, HelloDoor, RemotePE, DPAPILoader/RemotePELoader, Grandoreiro, BTMOB) and abusing developer and endpoint infrastructure. Active exploitation of critical flaws includes a Gogs authenticated RCE (CVSS 9.4, no CVE assigned), Ghost CMS CVE-2026-26980 (SQLi, CVSS 9.4) used to hijack sites, and ongoing exploitation of a FortiClient EMS flaw to配送
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5629211b94e4d3df7ec6a0858c42ddfc3274fe77965811ad398a6e4841ea2c47
- Enrichment time
- 2026-05-29T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.