2025년 3월 PebbleDash 악성코드 유포 사례

2025-04-22 Ahnlab Cyber threat report on Kimsuky, PebbleDash

https://asec.ahnlab.com/ko/87613/

Thumbnail for 2025년 3월 PebbleDash 악성코드 유포 사례

ASEC documents March 2025 distribution of the PebbleDash backdoor in activity it attributes to Kimsuky, noting that PebbleDash was originally named by CISA as Lazarus/Hidden Cobra malware but has recently appeared frequently in Kimsuky cases. The attack chain begins with spear-phishing that delivers a malicious LNK, which launches JavaScript through mshta.exe and then PowerShell. The PowerShell stage establishes persistence through scheduled tasks and Run keys, communicates with Dropbox and attacker C2 infrastructure, and deploys PebbleDash, AsyncRAT, patched RDP components, UAC-bypass tooling, and ForceCopy for data theft. The report highlights a shift from using RDP Wrapper toward directly patched termsrv.dll for terminal-service access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 70d92e2b00ec6702e17e266b7742bbab 2025-04-22 2025-04-23
HASH 641593eea5f235e27d7cff27d5b7ca2a 2025-04-22 2025-04-23

Related Actors

Related Reports

« Back