#PebbleDash

Malware/Tool

2020-05-12 • MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH

PebbleDash is a backdoor historically associated with Lazarus and increasingly reported in Kimsuky operations. It communicates with command-and-control infrastructure to steal information and execute commands; one analysis describes 28 supported commands and the ability to download and run remote-control or VNC malware. Recent delivery involved Kimsuky spear-phishing that impersonated diplomatic personnel, used malicious LNK files and diplomatic-themed decoys, and launched PowerShell, JavaScript, or HTA-based stages. Those chains installed PebbleDash alongside tools such as PrxClient, RDP Wrapper, UAC-bypass utilities, keyloggers, and downloaders.

Tagged Reports

« Back