PULSE NAME
Disclosing new PebbleDash-based tools
WHITE Kimsuky AlienVault 2026-05-14 Modified: 2026-05-14
50
IOCs
MEDIUM VOLUME
Kaspersky researchers conducted an in-depth analysis of Kimsuky APT activity, revealing tactical shifts and new malware variants based on the PebbleDash platform. The group introduced HelloDoor, a Rust-based backdoor, httpMalice leveraging HTTP and Dropbox communications, and updated MemLoad and httpTroy variants. Kimsuky maintains persistence through legitimate tools including VSCode Tunneling with GitHub authentication and DWAgent remote management software. Initial access occurs via spear-phishing with malicious attachments disguised as documents. The group primarily targets South Korean entities across government and defense sectors, with additional PebbleDash attacks observed in Brazil and Germany. Infrastructure relies on free South Korean hosting services and tunneling services like Cloudflare Quick Tunnels and Ngrok. Both PebbleDash and AppleSeed malware clusters demonstrate ongoing development with shared distribution methods, stolen certificates, and overlapping targets, indicating single-actor c...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
HelloDoor httpMalice MemLoad httpTroy AppleSeed - S0622 HappyDoor BabyShark - S0414 RandomQuery xRAT XenoRAT TutRAT httpSpy Troll Stealer ValleyRAT CoolClient ZiChatBot
Indicators of Compromise (19 / 50 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 08160acf08fccecde7b34090db18b321 2026-05-14
FileHash-MD5 52f1ff082e981cbdfd1f045c6021c63f 2026-05-14
FileHash-MD5 58ac2f65e335922be3f60e57099dc8a3 2026-05-14
FileHash-MD5 5c373c2116ab4a615e622f577e22e9be 2026-05-14
FileHash-MD5 65fc9f06de5603e2c1af9b4f288bb22c 2026-05-14
FileHash-MD5 678fb1a87af525c33ba2492552d5c0e2 2026-05-14
FileHash-MD5 7e0825019d0de0c1c4a1673f94043ddb 2026-05-14
FileHash-MD5 8983ffa6da23e0b99ccc58c17b9788c7 2026-05-14
FileHash-MD5 8e15c4d4f71bdd9dbc48cd2cabc87806 2026-05-14
FileHash-MD5 94faed9af49c98a89c8acc55e97276c9 2026-05-14
FileHash-MD5 995a0a49ae4b244928b3f67e2bfd7a6e 2026-05-14
FileHash-MD5 9ca5f93a732f404bbb2cee848f5bbda0 2026-05-14
FileHash-MD5 9fe43e08c8f446554340f972dac8a68c 2026-05-14
FileHash-MD5 a7f0a18ac87e982d6f32f7a715e12532 2026-05-14
FileHash-MD5 c19aeaedbbfc4e029f7e9bdface495b9 2026-05-14
FileHash-MD5 c42ae004badddd3017adadbdd1421e00 2026-05-14
FileHash-MD5 d1ec20144c83bba921243e72c517da5e 2026-05-14
FileHash-MD5 f4465403f9693939fe9c439f0ab33610 2026-05-14
FileHash-MD5 f73ba062116ea9f37d072aa41c7f5108 2026-05-14