Kimsuky hackers use new custom RDP Wrapper for remote access
ID: e4a7c88f-c582-5107-97ba-a7304593d47f
STIX ID: report--e4a7c88f-c582-5107-97ba-a7304593d47f
Feed Name: Bleeping Computer
Threat Score
ASEC observed North Korean APT Kimsuky conducting spear-phishing attacks that drop PebbleDash and a modified open-source RDP Wrapper plus proxy tools to obtain stealthy, persistent RDP access; secondary payloads include keyloggers, a browser credential stealer (forceCopy), and a PowerShell reflective loader, indicating an evolution toward quieter remote-access TTPs for prolonged espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
