PebbleDash와 RDP Wrapper를 악용한 Kimsuky 그룹의 최신 공격 사례 분석
2024-10-23 • Ahnlab • Analysis of Recent Kimsuky Attacks Abusing PebbleDash and RDP Wrapper •
AhnLab reports that Kimsuky has used LNK-based spear-phishing to install PowerShell malware and maintain execution through scheduled VBS scripts. The activity downloads additional payloads, commonly including RDP Wrapper, to enable remote control of compromised systems, create backdoor accounts, and support attacker access through RDP. The report also notes use of custom proxy malware and recent PebbleDash activity, tying the campaign to espionage-focused targeting of defense, media, diplomatic, government, and academic organizations.
Related Actors
Related Reports
Shares tags: Kimsuky, PebbleDash • Same author: Ahnlab
Shares tags: Kimsuky, PebbleDash • Same author: Ahnlab
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tags: Kimsuky, PebbleDash • Same author: Ahnlab
Shares tags: Kimsuky, PebbleDash • Same author: Ahnlab
Shares tags: Kimsuky, PebbleDash