PebbleDash와 RDP Wrapper를 악용한 Kimsuky 그룹의 최신 공격 사례 분석

2024-10-23 Ahnlab Analysis of Recent Kimsuky Attacks Abusing PebbleDash and RDP Wrapper

https://asec.ahnlab.com/ko/84066/

Thumbnail for PebbleDash와 RDP Wrapper를 악용한 Kimsuky 그룹의 최신 공격 사례 분석

AhnLab reports that Kimsuky has used LNK-based spear-phishing to install PowerShell malware and maintain execution through scheduled VBS scripts. The activity downloads additional payloads, commonly including RDP Wrapper, to enable remote control of compromised systems, create backdoor accounts, and support attacker access through RDP. The report also notes use of custom proxy malware and recent PebbleDash activity, tying the campaign to espionage-focused targeting of defense, media, diplomatic, government, and academic organizations.

Related Actors

Related Reports

« Back