북한발 PebbleDash 백도어 악성코드 분석

2025-05-08 Igloo Analysis of North Korea-Origin PebbleDash Backdoor Malware

https://www.igloopedia.com/1caf216a-760c-806e-95ac-ca95991541b6

Thumbnail for 북한발 PebbleDash 백도어 악성코드 분석

The report analyzes PebbleDash, a backdoor historically associated with Lazarus and more recently observed in activity linked to Kimsuky. The malware appears to depend on a preceding loader or installation stage to place configuration data and persistence artifacts, including registry-stored configuration under a WMI Security path. Once running, PebbleDash can connect to C2 infrastructure and execute a broad command set, including information theft, command execution, file operations, remote-control tooling, and anti-forensic deletion. The sample also uses obfuscation, XOR decoding, encrypted strings, and encrypted network communication to complicate analysis and detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 31345cc286bfb2b3edcee6c960f11c3f 2025-05-08 2025-05-19
HASH 815eabbaecd9b763d6c63f6a94c25ac0 2025-05-08 2025-05-08

Related Actors

Related Reports

« Back