PebbleDash is a Windows backdoor associated with North Korean cyber operations and most prominently linked to Kimsuky, while earlier public reporting also tied it to Lazarus and HIDDEN COBRA activity. It has been used in espionage-oriented intrusions against South Korean and other targets, including diplomacy-, defense-, government-, education-, and enterprise-related victims. The malware has appeared both as a standalone beaconing implant and as part of broader intrusion chains involving additional tooling such as proxy malware, keyloggers, RDP-enablement utilities, and other Kimsuky malware families.
PebbleDash provides remote control over compromised hosts through command-and-control communications that support system enumeration, process management, command execution, and file operations including upload, download, deletion, and execution. Reported variants can enable Windows command-line access, create and terminate processes, list directories, modify configuration, and self-delete. Some samples use obfuscated imports and custom string decoding, and at least one well-documented variant disguises network traffic with a FakeTLS handshake before switching to RC4-encrypted command traffic.
Operationally, PebbleDash has been delivered through spearphishing campaigns using compressed attachments, malicious shortcut files, and droppers in script and executable formats. Kimsuky campaigns have used LNK-based infection chains with diplomatic or business-themed decoys to install PebbleDash alongside supporting tools for persistence, privilege escalation, proxying, keylogging, and RDP access. Additional observed delivery chains have relied on PIF, JSE, SCR, and EXE droppers. Some variants require specific command-line arguments to install or activate, copy themselves into masqueraded locations, store configuration data in the Windows registry, or inject into other processes.
The malware is best characterized as a backdoor used for sustained access and follow-on exploitation in targeted intrusions. Its recurring use across multiple campaigns, overlap with other DPRK malware ecosystems, and appearance in both Lazarus- and Kimsuky-linked operations make it notable both as an operational implant and as an example of tooling reuse or transfer across North Korean threat clusters.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
5.3. Privilege Escalation …….. 5.3.1. UACMe …….. 5.3.2. CVE-2021-1675 Vulnerability
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The reports outline three different malware types: PebbleDash Trojan, TaintedScribe Trojan and CopperHedge RAT.
Malware used by the Kimsuky group not only include custom-made such as AppleSeed and PebbleDash, but also open-source or commercial malware such as XRat, HVNC, Amadey, and Metasploit Meterpreter.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
The two Trojans, PebbleDash and TaintedScribe are beaconing implants that can be used to exfiltrate information, download additional malicious content and execute commands on infected devices. CopperHedge is a variant of the Manuscrypt RAT and is a remote access tool that can be used to run arbitrary commands...
It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
The sample obfuscates strings used for API lookups using a custom XOR algorithm.
The sample performs dynamic dynamic link library (DLL) importing and application programming interface (API) lookups using LoadLibrary and GetProcAddress on obfuscated strings in an attempt to hide it’s usage of network functions.
The dropper drops PebbleDash in the “C:\ProgramData\thumbs.db.pif” path and runs it. At the same time, it also drops and runs the “C:\ProgramData\construction completion notice.pdf” file to trick the user into thinking that a normal PDF document file has been opened.
Once the FakeTLS handshake is complete, all further packets use a FakeTLS header, followed by RC4 encrypted data.
The sample and the command and control (C2) externally appear to perform a standard TLS authentication, however, most of the fields used are filled with random data from rand().
FBI has high confidence that HIDDEN COBRA actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation. | The sample utilizes a “FakeTLS” scheme in an attempt to obfuscate its network communications.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimsuky-linked spear-phishing campaign installs PebbleDash as the primary backdoor for remote control. It supports C2 communications, system and drive enumeration, command execution, file upload/download, process execution/termination, configuration changes, heartbeat, and self-deletion. A second variant stores configuration in the registry and injects PebbleDash into LSASS via an injector DLL.
Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
Backdoor malware used by Kimsuky to gain control of infected systems. It installs itself, communicates with a C2 server, supports command execution, file upload/download, process and system information collection, configuration changes, heartbeat, and self-delete. A second variant stores configuration in the registry and injects PebbleDash into LSASS for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.