Research Report
Threat Analysis

From Lazarus to Kimsuky: The Evolution of PebbleDash Malware

Summary


PebbleDash, a backdoor malware named by the US CISA in 2020 and attributed to the Lazarus group, has been used in attacks by the Kimsuky group


Distribution Method 

•   Initial infiltration happens with a spear phishing LNK file
•   Distribution begins with the execution of a malicious script embedded in the file 


Techniques 

•   Use of PowerShell to register tasks in Task Scheduler, add autorun entries to the registry, and establish C&C communication via Dropbox and TCP sockets 
•   Use of additional malware to bypass RDP authentication and take control by using Async RAT, a UAC bypass technique, and a patched termsrrv.dll


Overview


The PebbleDash backdoor malware was named in 2020 by CISA, an agency under the US Department of Homeland Security, as a backdoor attributed to Lazarus (Hidden Cobra). While it was initially recognized as malware used by the Lazarus group, it has recently been more frequently observed in attacks by the Kimsuky group, which is known for distributing malware to individuals. This report aims to cover the latest distribution process of the PebbleDash malware used by the Kimsuky group, along with the Async RAT, keylogger, UAC bypass techniques, and RDP-related modules identified with it.

 

As mentioned in several previous TI reports, the Kimsuky group has been known to use the open-source tool RDP Wrapper for remote control alongside PebbleDash. However, more recent cases show the group directly patching the termsrv.dll file, which serves the terminal service role, to achieve the same goal.

 

Below, Figure 1 illustrates the latest attack process involving PebbleDash by the Kimsuky group.


Figure 1. Latest PebbleDash malware attack process by the Kimsuky group




 

▶ Download Report

View as PDF