Kimsuky targets organizations with PebbleDash-based tools
ID: 32c01988-e4d9-57d4-8969-e6d329085aef
STIX ID: report--32c01988-e4d9-57d4-8969-e6d329085aef
Feed Name: Securelist by Kaspersky
Kaspersky analyzed ongoing Kimsuky (APT43) campaigns showing evolution of the PebbleDash and AppleSeed clusters: targeted spear-phishing with JSE/EXE/SCR/PIF droppers delivering backdoors (HelloDoor, httpMalice, httpTroy) and loaders (MemLoad), post-exploitation using legitimate tools (VSCode Remote Tunneling, DWAgent), use of tunneling services and hijacked/free South Korean domains for C2, and detailed IoCs (file hashes, domains) and behavioral indicators tied to operations against South Korean public and private sector entities and select international defense targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
