Disclosing new PebbleDash-based tools
· Published 14/05/2026 13:16 · Modified 14/05/2026 18:13
Essential information
- Published
- 14/05/2026 13:16
- Modified
- 14/05/2026 18:13
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- appleseed babyshark coolclient dwagent happydoor hellodoor httpmalice httpspy httptroy kimsuky memload pebbledash randomquery south korea spear-phishing troll stealer tutrat valleyrat vscode tunneling xenorat xrat zichatbot
- Tags
- 2026-05-14 appleseed babyshark coolclient dwagent happydoor hellodoor httpmalice httpspy httptroy kimsuky memload pebbledash randomquery south korea spear-phishing troll stealer tutrat valleyrat vscode tunneling xenorat xrat zichatbot
- Related entities
- 25 indicators, 25 observables, 1 intrusion sets (apt), 20 techniques (mitre), 16 malware, 21 others
Description
Kaspersky researchers conducted an in-depth analysis of Kimsuky APT activity, revealing tactical shifts and new malware variants based on the PebbleDash platform. The group introduced HelloDoor, a Rust-based backdoor, httpMalice leveraging HTTP and Dropbox communications, and updated MemLoad and httpTroy variants. Kimsuky maintains persistence through legitimate tools including VSCode Tunneling with GitHub authentication and DWAgent remote management software. Initial access occurs via spear-phishing with malicious attachments disguised as documents. The group primarily targets South Korean entities across government and defense sectors, with additional PebbleDash attacks observed in Brazil and Germany. Infrastructure relies on free South Korean hosting services and tunneling services like Cloudflare Quick Tunnels and Ngrok. Both PebbleDash and AppleSeed malware clusters demonstrate ongoing development with shared distribution methods, stolen certificates, and overlapping targets, indicating single-actor c...
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Indicators (25)
-
d0912a47413338a1a79eef767aa33135f1e3ac66dfb6f6d1c8dbec72c892b985 -
node896147.dwservice.net -
attach.docucloud.o-r.kr -
erp.spaceme.p-e.kr -
https://file.bigcloud.n-e.kr/index.php -
4ac02dc231f2546ce64335729145db672b5ab01d8943df8a550cc77fc436df14 -
load.auraria.org -
2d597c3a726970927b302bf015cec4e37cdc974959cb846dbcb23cdb46386a6c -
8779580d97d5a1d9c612cee745a7097483fc1643e38d7c1574670f56bc7abb48 -
http://newjo-imd.com/common/include/library/default.php -
load.erasecloud.n-e.kr -
cms.spaceyou.o-r.kr -
http://female-disorder-beta-metropolitan.trycloudflare.com/index.php -
load.yju.o-r.kr -
load.supershop.o-r.kr -
female-disorder-beta-metropolitan.trycloudflare.com -
https://www.yespp.co.kr/common/include/code/out.php -
morames.r-e.kr -
node828765.dwservice.net -
newjo-imd.com -
file.bigcloud.n-e.kr -
https://www.pyrotech.co.kr/common/include/tech/default.php -
opedromos1.r-e.kr -
node484265.dwservice.net -
load.ssangyongcne.o-r.kr
Observables (25)
newjo-imd.comload.erasecloud.n-e.krnode484265.dwservice.netopedromos1.r-e.krnode828765.dwservice.netattach.docucloud.o-r.krmorames.r-e.krnode896147.dwservice.netload.auraria.orgload.ssangyongcne.o-r.krcms.spaceyou.o-r.krload.supershop.o-r.krfile.bigcloud.n-e.krerp.spaceme.p-e.krload.yju.o-r.krfemale-disorder-beta-metropolitan.trycloudflare.comhttps://file.bigcloud.n-e.kr/index.phphttp://newjo-imd.com/common/include/library/default.phphttps://www.yespp.co.kr/common/include/code/out.phphttps://www.pyrotech.co.kr/common/include/tech/default.phphttp://female-disorder-beta-metropolitan.trycloudflare.com/index.phpd0912a47413338a1a79eef767aa33135f1e3ac66dfb6f6d1c8dbec72c892b9854ac02dc231f2546ce64335729145db672b5ab01d8943df8a550cc77fc436df142d597c3a726970927b302bf015cec4e37cdc974959cb846dbcb23cdb46386a6c8779580d97d5a1d9c612cee745a7097483fc1643e38d7c1574670f56bc7abb48
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33
Techniques (MITRE) (20)
-
Process Injection
-
Keylogging
-
Web Protocols
-
PowerShell
-
Malicious File
-
Modify Registry
-
Scheduled Task
-
Spearphishing Attachment
-
Windows Command Shell
-
Data from Local System
-
Obfuscated Files or Information
-
Remote Access Tools
-
Registry Run Keys / Startup Folder
-
Standard Encoding
-
Symmetric Cryptography
-
Internal Proxy
-
Windows Service
-
Deobfuscate/Decode Files or Information
-
Screen Capture
-
Exfiltration Over C2 Channel
Malware (16)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:41 · Modified 21/12/2025 03:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 29/05/2026 10:49 · Modified 29/05/2026 10:49
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
FamilyPublished 29/05/2026 11:20 · Modified 29/05/2026 11:20
-
FamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
Others (21)
- Energy
- Manufacturing
- Health
- Government and administrations
- Defense
- node896147.dwservice.net
- attach.docucloud.o-r.kr
- erp.spaceme.p-e.kr
- load.auraria.org
- load.erasecloud.n-e.kr
- cms.spaceyou.o-r.kr
- load.yju.o-r.kr
- load.supershop.o-r.kr
- female-disorder-beta-metropolitan.trycloudflare.com
- morames.r-e.kr
- node828765.dwservice.net
- newjo-imd.com
- file.bigcloud.n-e.kr
- opedromos1.r-e.kr
- node484265.dwservice.net
- load.ssangyongcne.o-r.kr