RDP Wrapper를 활용한 Kimsuky 그룹의 지속적인 위협
2025-02-04 • Ahnlab • Persistent Kimsuky Threat Using RDP Wrapper •
ASEC reports continued Kimsuky activity involving spear-phishing lures, malicious shortcut files, PebbleDash, and custom use of RDP Wrapper to maintain access. The source notes that file names contain personal or company-specific details, indicating targeted victim research before delivery. The activity reinforces Kimsuky persistence tradecraft around remote access tooling and backdoors, and defenders should monitor for suspicious LNK execution, RDP Wrapper artifacts, and PebbleDash-related indicators.
Related Actors
Related Reports
Shares tags: Kimsuky, LNK • Same author: Ahnlab • Published within a week
Shares tags: Kimsuky, LNK • Published within a month
Shares tags: Kimsuky, LNK • Published within a month
2025-02-13 •
80% Match
Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks
Securonix
Shares tags: Kimsuky, LNK • Published within a month
Shares tags: Kimsuky, LNK • Published within a week
Shares tags: Kimsuky, LNK • Published within a week