logo

Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

ID: 450ac4eb-8b7d-5a03-a670-fcab02adc7f5

STIX ID: report--450ac4eb-8b7d-5a03-a670-fcab02adc7f5

Feed Name: ASEC

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-07-23

Author: ATCP

...
...

This report documents Kimsuky spear-phishing campaigns in 2026 that use LNK/HTA droppers to deploy PebbleDash backdoors, PrxClient proxy tools, RDP wrapper/backdoor accounts, UAC bypass utilities, and keyloggers; it details delivery and persistence TTPs, command-and-control protocols, supported commands, privilege escalation and RDP patching, and includes multiple IOCs (MD5s, URLs, FQDNs, IPs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.