PrxClient is a proxy utility associated with Kimsuky spear-phishing operations observed in 2026. It was used in campaigns that impersonated diplomats and targeted diplomacy-related personnel, with additional reporting indicating targeting of individuals in the education sector. The broader intrusion set relied on malicious LNK files and script-based execution chains to deploy multiple components, including PebbleDash, RDP-enablement tooling, UAC bypass utilities, keyloggers, and PrxClient.
PrxClient functions as a relay between attacker-controlled infrastructure and local services on a compromised Windows host. Observed use indicates it forwarded traffic to the local Remote Desktop service, supporting covert remote administration of infected systems in conjunction with RDP Wrapper, RDP patching, and attacker-created or enabled backdoor accounts. In this role, PrxClient served as post-compromise access infrastructure rather than an initial infection payload.
The malware was deployed as part of spear-phishing attacks using diplomatic-themed decoy documents and malicious shortcut files. Those LNK-based chains launched PowerShell or embedded HTA content to install follow-on tooling, establish persistence, and retrieve additional payloads. Within that ecosystem, PrxClient complemented PebbleDash and other utilities by enabling proxy-based access to internal services on victim machines.
High-confidence reporting supports classifying PrxClient as threat-actor-developed proxy malware used by Kimsuky for remote access support on compromised Windows systems. Its observed purpose was to tunnel traffic to local ports, especially for RDP-enabled control after initial compromise and privilege escalation steps had already been performed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy utility used to relay traffic between a C2 server and a local port, likely to enable attacker RDP access to compromised hosts.
Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
Proxy malware/tool that relays traffic between a C2 server and a local port, likely enabling the threat actor to control infected systems via RDP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.