북한발 PebbleDash 백도어 악성코드 분석
2025-05-08 • Igloo • Analysis of North Korea-Origin PebbleDash Backdoor Malware •
https://www.igloopedia.com/1caf216a-760c-806e-95ac-ca95991541b6
The report analyzes PebbleDash, a backdoor historically associated with Lazarus and more recently observed in activity linked to Kimsuky. The malware appears to depend on a preceding loader or installation stage to place configuration data and persistence artifacts, including registry-stored configuration under a WMI Security path. Once running, PebbleDash can connect to C2 infrastructure and execute a broad command set, including information theft, command execution, file operations, remote-control tooling, and anti-forensic deletion. The sample also uses obfuscation, XOR decoding, encrypted strings, and encrypted network communication to complicate analysis and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 31345cc286bfb2b3edcee6c960f11c3f | 2025-05-08 | 2025-05-19 |
| HASH | 815eabbaecd9b763d6c63f6a94c25ac0 | 2025-05-08 | 2025-05-08 |