Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

2026-07-17 Ahnlab

https://asec.ahnlab.com/en/94552/

Thumbnail for Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

Kimsuky continued spear-phishing operations in 2026 by impersonating diplomatic personnel and using malicious LNK attachments with diplomatic-themed decoy documents. The infection chains deployed PebbleDash for remote control, PrxClient to relay C2 traffic to local RDP, and additional tools for privilege escalation, keylogging, downloading, persistence, and file exfiltration. PebbleDash variants either installed themselves with command-line arguments or injected into LSASS after storing C2 configuration in the registry. ASEC said the recent activity targeted people in the education sector.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 173.214.170.58 2026-07-17 2026-07-23
IPv4 153.75.233.17 2026-07-17 2026-07-23
IPv4 103.212.120.253 2026-07-17 2026-07-23
DOMAIN p563q1.sportsontheweb.net 2026-07-17 2026-07-23
DOMAIN ng.mofagov.com 2026-07-17 2026-07-23
DOMAIN mpo4wj.scienceontheweb.net 2026-07-17 2026-07-23
DOMAIN fsfhsfgsfsnxcvbasfsgsrhsf234fsd… 2026-07-17 2026-07-23
URL http://edcvbgtrf.medianewsonlin… 2026-07-17 2026-07-23
URL http://edcvbgtrf.medianewsonlin… 2026-07-17 2026-07-23
URL http://edcvbgtrf.medianewsonlin… 2026-07-17 2026-07-23
DOMAIN edcvbgtrf.medianewsonline.com 2026-07-17 2026-07-23
URL http://edcvbgtrf.medianewsonlin… 2026-07-17 2026-07-23
URL http://167.88.165.122/login.asp 2026-07-17 2026-07-23
HASH 0c0a44de58b0a47b749411a9c2fe178e 2026-07-17 2026-07-23
HASH 0a5f8bb2aebb296b6a5048ca5b85d8ad 2026-07-17 2026-07-23
HASH 07010ef323ff1a6efebf9c59f8afb35f 2026-07-17 2026-07-23
HASH 029db651367bb1eac0a85bd826afe420 2026-07-17 2026-07-23
HASH 00f27b3cf8817313aafdfc29ff238153 2026-07-17 2026-07-23

Related Actors

Related Reports

« Back