Kimsuky 그룹의 APT 공격사례 (PebbleDash)

2021-12-21 Ahnlab APT attack case by Kimsuky group (PebbleDash)

https://asec.ahnlab.com/ko/29718/

Thumbnail for Kimsuky 그룹의 APT 공격사례 (PebbleDash)

AhnLab describes a Kimsuky spearphishing case in which a link presented as an attachment led victims to a ZIP file containing a PIF dropper for the PebbleDash backdoor. The dropper installs PebbleDash under C:\ProgramData, opens a decoy Korean PDF, and the backdoor accepts attacker commands for process and file operations plus upload and download, giving operators control of the host. The report also links the environment to VBS downloader activity used with AppleSeed droppers, scheduled tasks that execute VBScript and regsvr32 payloads, AppleSeed installation under software-like paths, and Meterpreter logs on related systems. Representative indicators include hxxp://tools.macbook.kro[.]kr/update.php and hxxp://m.sharing.p-e[.]kr/index.php?query=me, along with MD5 hashes for PebbleDash droppers and VBS downloaders.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 71fe5695bd45b72a8bb864636d92944b 2021-12-21 2021-12-21
HASH 269ded557281d38b5966d6227c757e92 2021-12-21 2021-12-21
HASH 25f057bff7de9d3bc2fb325697c56334 2021-12-21 2021-12-21
HASH 7211fed2e2ec624c87782926200d61fd 2021-12-21 2021-12-21
URL http://m.sharing.p-e.kr/index.p… 2021-12-21 2021-12-21
URL http://tools.macbook.kro.kr/upd… 2021-12-21 2021-12-21
DOMAIN m.sharing.p-e.kr 2021-12-21 2021-12-21
DOMAIN tools.macbook.kro.kr 2021-12-21 2021-12-21

Related Actors

Related Reports

« Back