Disclosing new PebbleDash-based tools by Kimsuky

2026-05-14 Kaspersky

https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/

Thumbnail for Disclosing new PebbleDash-based tools by Kimsuky

Kimsuky has expanded its PebbleDash and AppleSeed-related operations with newly documented tooling, including the Rust-based HelloDoor backdoor, httpMalice, MemLoad/httpTroy, AppleSeed, HappyDoor, VSCode Remote Tunneling, and DWAgent. The campaigns use spear-phishing attachments and varied droppers to compromise mainly South Korean public and private entities, with PebbleDash-linked activity also observed against defense organizations in Brazil and Germany. Kaspersky found overlapping distribution methods, target sectors, certificates, mutex patterns, and infrastructure between the PebbleDash and AppleSeed clusters, supporting medium-high confidence attribution to Kimsuky-affiliated clusters. The report highlights Kimsuky's use of legitimate remote access and tunneling services, Korean-language host profiling behavior, possible LLM-assisted Rust malware development, and C2 infrastructure hosted through free Korean domains, compromised websites, Cloudflare tunnels, and Dropbox.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN load.erasecloud.n-e.kr 2026-05-14 2026-05-27
HASH 23420100260cc80055fbf02f4464212… 2026-05-14 2026-05-15
HASH 8b10ac9520a1ef24cf2269ec9ee4554… 2026-05-14 2026-05-15
HASH 59eb093c10f11f612b8dadab258285a… 2026-05-14 2026-05-15
URL https://www.pyrotech.co.kr/comm… 2026-05-14 2026-05-15
DOMAIN www.pyrotech.co.kr 2026-05-14 2026-05-15
DOMAIN www.yespp.co.kr 2026-05-14 2026-05-15
URL https://www.yespp.co.kr/common/… 2026-01-21 2026-05-15
DOMAIN node484265.dwservice.net 2026-05-14 2026-05-14
DOMAIN node828765.dwservice.net 2026-05-14 2026-05-14
DOMAIN node896147.dwservice.net 2026-05-14 2026-05-14
URL http://newjo-imd.com/common/inc… 2026-05-14 2026-05-14
URL https://file.bigcloud.n-e.kr/in… 2026-05-14 2026-05-14
URL http://female-disorder-beta-met… 2026-05-14 2026-05-14
DOMAIN female-disorder-beta-metropolit… 2026-05-14 2026-05-14
DOMAIN file.bigcloud.n-e.kr 2026-05-14 2026-05-14
DOMAIN erp.spaceme.p-e.kr 2026-05-14 2026-05-14
DOMAIN cms.spaceyou.o-r.kr 2026-05-14 2026-05-14
DOMAIN load.supershop.o-r.kr 2026-05-14 2026-05-14
DOMAIN attach.docucloud.o-r.kr 2026-05-14 2026-05-14
DOMAIN load.yju.o-r.kr 2026-05-14 2026-05-14
DOMAIN load.ssangyongcne.o-r.kr 2026-05-14 2026-05-14
DOMAIN morames.r-e.kr 2026-05-14 2026-05-14
DOMAIN opedromos1.r-e.kr 2026-05-14 2026-05-14
HASH 678fb1a87af525c33ba2492552d5c0e2 2026-05-14 2026-05-14
HASH 9ca5f93a732f404bbb2cee848f5bbda0 2026-05-14 2026-05-14
HASH 62aac86f38f26700cf534c0a316d318… 2026-05-14 2026-05-14
HASH 94faed9af49c98a89c8acc55e97276c9 2026-05-14 2026-05-14
HASH 7e0825019d0de0c1c4a1673f94043ddb 2026-05-14 2026-05-14
HASH f73ba062116ea9f37d072aa41c7f5108 2026-05-14 2026-05-14
HASH 2d597c3a726970927b302bf015cec4e… 2026-05-14 2026-05-14
HASH 0845f218a588f7619169787c4db69ce… 2026-05-14 2026-05-14
HASH 929dbf16ee3a1b088d09dac820058c0… 2026-05-14 2026-05-14
HASH 410a58e4799e7af4408ab5ba917d93c… 2026-05-14 2026-05-14
HASH d0912a47413338a1a79eef767aa3313… 2026-05-14 2026-05-14
HASH c19aeaedbbfc4e029f7e9bdface495b9 2026-05-14 2026-05-14
HASH 65fc9f06de5603e2c1af9b4f288bb22c 2026-05-14 2026-05-14
HASH 38537c172dec2b985bd7e81d8a8aae7… 2026-05-14 2026-05-14
HASH db284cc9b6536ab6f956a45ce9e5905… 2026-05-14 2026-05-14
DOMAIN newjo-imd.com 2026-03-19 2026-05-14
DOMAIN load.auraria.org 2025-10-30 2026-05-14
HASH d1ec20144c83bba921243e72c517da5e 2025-07-08 2026-05-14

Related Actors

Related Reports

2026-04-17 • 54% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing, T1041 • Published within a month
« Back