#PrxClient
Malware/Tool
2026-07-17 • Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
PrxClient is proxy malware installed during Kimsuky spear-phishing attacks that impersonated diplomatic personnel and used diplomatic-themed documents as lures. Malicious LNK attachments launched PowerShell or mshta-based droppers, established scheduled-task persistence, displayed decoy documents, and downloaded additional payloads. The broader toolset included PebbleDash, RDP Wrapper, UAC bypass utilities, keyloggers, launchers, and downloaders. In compromised Windows environments, PrxClient provided proxy capability alongside remote-control, credential-capture, privilege-escalation, and data-exfiltration components used for sustained access.
-
2
Tagged Reports
-
1
Unique Authors
-
7
Active Days