Kimsuky 그룹의 APT 공격사례 (PebbleDash)
2021-12-21 • Ahnlab • APT attack case by Kimsuky group (PebbleDash) •
AhnLab describes a Kimsuky spearphishing case in which a link presented as an attachment led victims to a ZIP file containing a PIF dropper for the PebbleDash backdoor. The dropper installs PebbleDash under C:\ProgramData, opens a decoy Korean PDF, and the backdoor accepts attacker commands for process and file operations plus upload and download, giving operators control of the host. The report also links the environment to VBS downloader activity used with AppleSeed droppers, scheduled tasks that execute VBScript and regsvr32 payloads, AppleSeed installation under software-like paths, and Meterpreter logs on related systems. Representative indicators include hxxp://tools.macbook.kro[.]kr/update.php and hxxp://m.sharing.p-e[.]kr/index.php?query=me, along with MD5 hashes for PebbleDash droppers and VBS downloaders.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 71fe5695bd45b72a8bb864636d92944b | 2021-12-21 | 2021-12-21 |
| HASH | 269ded557281d38b5966d6227c757e92 | 2021-12-21 | 2021-12-21 |
| HASH | 25f057bff7de9d3bc2fb325697c56334 | 2021-12-21 | 2021-12-21 |
| HASH | 7211fed2e2ec624c87782926200d61fd | 2021-12-21 | 2021-12-21 |
| URL | http://m.sharing.p-e.kr/index.p… | 2021-12-21 | 2021-12-21 |
| URL | http://tools.macbook.kro.kr/upd… | 2021-12-21 | 2021-12-21 |
| DOMAIN | m.sharing.p-e.kr | 2021-12-21 | 2021-12-21 |
| DOMAIN | tools.macbook.kro.kr | 2021-12-21 | 2021-12-21 |