logo

Persistent Threats from the Kimsuky Group Using RDP Wrapper

ID: cfa6a41e-d479-5f79-8cc1-a85411e78fd4

STIX ID: report--cfa6a41e-d479-5f79-8cc1-a85411e78fd4

Feed Name: ASEC

Threat Score
78/100

Date Published: 2025-02-03

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC reports on Kimsuky’s ongoing spear-phishing campaign using malicious .LNK files that launch PowerShell or mshta to retrieve payloads — notably the PebbleDash backdoor and a custom RDP Wrapper — and also employing proxies, keyloggers, an infostealer called forceCopy, and loader/injector components; the report includes sample detections, MD5 hashes, IPs, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.