North Korea’s ‘HttpTroy’ Backdoor Exposed – Inside the Stealth Hack Shaking Cybersecurity and Stocks
Kimsuky’s “HttpTroy” – A Fake VPN Invoice with a Real Backdoor A new threat actor playbook has emerged from North Korea’s shadowy cyber-espionage operations. In early November 2025, researchers revealed that the DPRK-linked group Kimsuky (aka Velvet Chollima or Thallium) deployed a previously unknown malware dubbed “HttpTroy.” The twist? Kimsuky’s hackers delivered this backdoor under the guise of an innocuous VPN invoice email webpronews.com. The phishing emails were crafted to look like legitimate billing notices for a VPN service – a lure likely to trick busy professionals, especially in South Korean government and defense circles, which Kimsuky often targets webpronews.com.