PebbleDash is a Windows backdoor and beaconing implant associated with North Korean threat activity. It has historically been linked to Lazarus and HIDDEN COBRA reporting, and more recent operations have also tied it to Kimsuky campaigns, indicating either tool sharing, reuse, or operational overlap among DPRK-linked clusters. PebbleDash is also described as a NukeSped variant and has appeared alongside other Kimsuky tooling such as AppleSeed, proxy malware, RDP-enablement utilities, keyloggers, and privilege-escalation tools.
PebbleDash provides remote control of compromised systems through command-and-control communications that support target enumeration, command execution, process creation and termination, file upload and download, file deletion, and execution of additional payloads. Reported variants can enable Windows command-line access, modify configuration, and self-delete. Some samples use FakeTLS to disguise network traffic and RC4-encrypted communications after an initial fake handshake. Other observed variants store configuration data in the Windows registry and use process injection, including injection into LSASS, to evade detection and maintain execution.
In Kimsuky intrusions, PebbleDash has commonly been delivered through spear-phishing lures using disguised attachments, including malicious LNK and PIF files, compressed archives, and script-based droppers. These infection chains often display decoy documents to reduce suspicion while installing the malware in the background. Related campaigns have targeted diplomacy, defense, academia, public institutions, and other South Korean organizations and individuals, with some reporting also noting activity against foreign targets. Post-compromise tradecraft observed with PebbleDash includes deployment of proxy tools, RDP Wrapper, multi-session RDP patching, hidden or enabled administrator accounts, UAC bypass tooling, and information theft components, showing its role as a central access-enablement backdoor within broader espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
5.3. Privilege Escalation …….. 5.3.1. UACMe …….. 5.3.2. CVE-2021-1675 Vulnerability
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware used by the Kimsuky group not only include custom-made such as AppleSeed and PebbleDash, but also open-source or commercial malware such as XRat, HVNC, Amadey, and Metasploit Meterpreter.
This malware variant has been identified as PEBBLEDASH... This report looks at a full-featured beaconing implant. This sample uses FakeTLS for session authentication and for network encoding utilizing RC4. It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
The sample obfuscates strings used for API lookups using a custom XOR algorithm.
The sample performs dynamic dynamic link library (DLL) importing and application programming interface (API) lookups using LoadLibrary and GetProcAddress on obfuscated strings in an attempt to hide it’s usage of network functions.
The dropper drops PebbleDash in the “C:\ProgramData\thumbs.db.pif” path and runs it. At the same time, it also drops and runs the “C:\ProgramData\construction completion notice.pdf” file to trick the user into thinking that a normal PDF document file has been opened.
Once the FakeTLS handshake is complete, all further packets use a FakeTLS header, followed by RC4 encrypted data.
The sample and the command and control (C2) externally appear to perform a standard TLS authentication, however, most of the fields used are filled with random data from rand().
FBI has high confidence that HIDDEN COBRA actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation. | The sample utilizes a “FakeTLS” scheme in an attempt to obfuscate its network communications.
FBI has high confidence that HIDDEN COBRA actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimsuky-linked spear-phishing campaign installs PebbleDash as the primary backdoor for remote control. It supports C2 communications, system and drive enumeration, command execution, file upload/download, process execution/termination, configuration changes, heartbeat, and self-deletion. A second variant stores configuration in the registry and injects PebbleDash into LSASS via an injector DLL.
Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
Backdoor malware used by Kimsuky to gain control of infected systems. It installs itself, communicates with a C2 server, supports command execution, file upload/download, process and system information collection, configuration changes, heartbeat, and self-delete. A second variant stores configuration in the registry and injects PebbleDash into LSASS for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.