logo

Kimsuky hackers use new custom RDP Wrapper for remote access

ID: e4a7c88f-c582-5107-97ba-a7304593d47f

STIX ID: report--e4a7c88f-c582-5107-97ba-a7304593d47f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-02-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ASEC observed North Korean APT Kimsuky conducting spear-phishing attacks that drop PebbleDash and a modified open-source RDP Wrapper plus proxy tools to obtain stealthy, persistent RDP access; secondary payloads include keyloggers, a browser credential stealer (forceCopy), and a PowerShell reflective loader, indicating an evolution toward quieter remote-access TTPs for prolonged espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.