PebbleDash is a Windows backdoor and beaconing implant associated with North Korean threat activity. It has historically been described as a NukeSped-related malware family linked to Lazarus and HIDDEN COBRA reporting, and more recent intrusion reporting places it prominently in Kimsuky spear-phishing operations. Kimsuky has also developed multiple follow-on tools and variants based on the PebbleDash platform, including families such as HelloDoor, HttpMalice, MemLoad, and HttpTroy.
PebbleDash is used to establish persistent remote control of compromised systems and execute attacker-supplied commands. Reported capabilities include host enumeration, process creation and termination, command execution through the Windows command line, file upload and download, file deletion, directory listing, configuration changes, and self-deletion. Some variants use FakeTLS-style session obfuscation with RC4-encrypted communications, while others have been observed using HTTP-based command channels with structured parameters. At least one reported variant stores configuration data in the registry and deploys an injector that places the backdoor into LSASS, indicating process-injection-based defense evasion.
In Kimsuky operations, PebbleDash commonly appears in multi-stage infection chains initiated through spear-phishing lures themed around diplomacy or other government-related subjects. Delivery has been observed through malicious LNK files as well as droppers in script and executable formats, including JSE, PIF, SCR, and EXE. These chains often invoke PowerShell or embedded HTA content to download and install PebbleDash alongside additional tooling such as proxy malware, RDP-enablement utilities, UAC bypass tools, and keyloggers. Persistence mechanisms observed in related campaigns include scheduled tasks and relaunch logic after self-copying.
Operationally, PebbleDash has been used against diplomacy-related personnel, government-linked targets, educational institutions, and defense-related organizations, with reporting centered heavily on South Korean targeting and some observations involving Brazil and Germany. In Kimsuky intrusions, PebbleDash has supported broader post-compromise activity including remote administration, data collection, exfiltration, and enabling interactive access through proxied or modified RDP workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
5.3. Privilege Escalation …….. 5.3.1. UACMe …….. 5.3.2. CVE-2021-1675 Vulnerability
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
A variant of this technique has been previously observed in the Pebbledash malware.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
This sample uses FakeTLS for session authentication and for network encoding utilizing RC4. It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
“%APPDATA%\Microsoft\Windows\Templates\Templates.js”와 ... “Templates.ps1”를 생성하고 “Windows Templates Update”라는 이름의 작업에 등록한다.
The sample obfuscates strings used for API lookups using a custom XOR algorithm... The sample obfuscates its callback descriptors (IP address and ports) using a different custom XOR algorithm.
The sample performs dynamic dynamic link library (DLL) importing and application programming interface (API) lookups using LoadLibrary and GetProcAddress on obfuscated strings in an attempt to hide it’s usage of network functions.
Normally, malware strains assumed to be attachments of spear phishing attack emails are disguised as document files. If a user runs the file, malware of this type runs the document that corresponds to the disguised file name and tricks the user into thinking that they have opened a normal file.
This sample uses FakeTLS for session authentication and for network encoding utilizing RC4. It has the capability to download, upload, delete, and execute files; enable Windows CLI access; create and terminate processes; and perform target system enumeration.
The sample utilizes a “FakeTLS” scheme in an attempt to obfuscate its network communications. The sample and the command and control (C2) externally appear to perform a standard TLS authentication, however, most of the fields used are filled with random data from rand().
They are both backdoors used by the Kimsuky group that can stay in the system and perform malicious behaviors by receiving commands from the attacker... 3.3. C&C Communications Using Emails ... Ping Thread (SMTP) ... Command Thread (IMAP) ... 4.1.3. C&C Communications ... 4.2.3. C&C Communications
FBI has high confidence that HIDDEN COBRA actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation.
Through communication with a Dropbox and TCP socket-based C&C server, the group installs multiple malware and tools including PEBBLEDASH.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimsuky-linked spear-phishing campaign installs PebbleDash as the primary backdoor for remote control. It supports C2 communications, system and drive enumeration, command execution, file upload/download, process execution/termination, configuration changes, heartbeat, and self-deletion. A second variant stores configuration in the registry and injects PebbleDash into LSASS via an injector DLL.
Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
Backdoor malware used by Kimsuky to gain control of infected systems. It installs itself, communicates with a C2 server, supports command execution, file upload/download, process and system information collection, configuration changes, heartbeat, and self-delete. A second variant stores configuration in the registry and injects PebbleDash into LSASS for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.