2025년 3월 PebbleDash 악성코드 유포 사례
2025-04-22 • Ahnlab • Cyber threat report on Kimsuky, PebbleDash •
ASEC documents March 2025 distribution of the PebbleDash backdoor in activity it attributes to Kimsuky, noting that PebbleDash was originally named by CISA as Lazarus/Hidden Cobra malware but has recently appeared frequently in Kimsuky cases. The attack chain begins with spear-phishing that delivers a malicious LNK, which launches JavaScript through mshta.exe and then PowerShell. The PowerShell stage establishes persistence through scheduled tasks and Run keys, communicates with Dropbox and attacker C2 infrastructure, and deploys PebbleDash, AsyncRAT, patched RDP components, UAC-bypass tooling, and ForceCopy for data theft. The report highlights a shift from using RDP Wrapper toward directly patched termsrv.dll for terminal-service access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 70d92e2b00ec6702e17e266b7742bbab | 2025-04-22 | 2025-04-23 |
| HASH | 641593eea5f235e27d7cff27d5b7ca2a | 2025-04-22 | 2025-04-23 |