logo

Kimsuky targets organizations with PebbleDash-based tools

ID: 32c01988-e4d9-57d4-8969-e6d329085aef

STIX ID: report--32c01988-e4d9-57d4-8969-e6d329085aef

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Sojun Ryu

...
...

Kaspersky analyzed ongoing Kimsuky (APT43) campaigns showing evolution of the PebbleDash and AppleSeed clusters: targeted spear-phishing with JSE/EXE/SCR/PIF droppers delivering backdoors (HelloDoor, httpMalice, httpTroy) and loaders (MemLoad), post-exploitation using legitimate tools (VSCode Remote Tunneling, DWAgent), use of tunneling services and hijacked/free South Korean domains for C2, and detailed IoCs (file hashes, domains) and behavioral indicators tied to operations against South Korean public and private sector entities and select international defense targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.