#PebbleDash
Malware/Tool
2020-05-12 • MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH
PebbleDash is a backdoor historically associated with Lazarus and increasingly reported in Kimsuky operations. It communicates with command-and-control infrastructure to steal information and execute commands; one analysis describes 28 supported commands and the ability to download and run remote-control or VNC malware. Recent delivery involved Kimsuky spear-phishing that impersonated diplomatic personnel, used malicious LNK files and diplomatic-themed decoys, and launched PowerShell, JavaScript, or HTA-based stages. Those chains installed PebbleDash alongside tools such as PrxClient, RDP Wrapper, UAC-bypass utilities, keyloggers, and downloaders.
-
14
Tagged Reports
-
8
Unique Authors
-
2,264
Active Days
Tagged Reports
2026-05-14
Kaspersky