Kimsuky continued spear phishing campaigns in 2026 by impersonating diplomatic personnel and using LNK files, PowerShell, and HTA content to deploy tools such as PebbleDash, PrxClient, RDP Wrapper, UACMe, and keyloggers. The attacks targeted education-sector users, enabled remote control and credential theft, and used infrastructure including edcvbgtrf[.]medianewsonline[.]com and IPs such as 153[.]75[.]233[.]17 and 173[.]214[.]170[.]58. #Kimsuky #PebbleDash #PrxClient #RDPWrapper #UACMe
Keypoints
- Kimsuky resumed spear phishing attacks in 2026 by impersonating diplomatic personnel.
- The attacks used LNK files, PowerShell scripts, and embedded HTA scripts to run malicious routines.
- PebbleDash was deployed as the main backdoor for remote control, with variants using command arguments or registry-stored configuration.
- The threat actor used RDP Wrapper, backdoor accounts, and an RDP patcher to enable multi-session remote access.
- PrxClient was used as a proxy relay between the C&C server and local RDP services.
- UAC bypass tools including UACMe and SspiUacBypass were used for privilege escalation.
- Keyloggers and downloaders were also observed for credential theft, data collection, and payload execution.
MITRE Techniques
- [T1566.001] Spearphishing Attachment – The attackers delivered malicious files through deceptive document-like attachments in spear phishing emails (‘spear phishing attacks by impersonating diplomatic personnel’ and ‘disguising them as document files’).
- [T1204.002] User Execution: Malicious File – The victim had to execute the LNK file or attached document to trigger the infection chain (‘When the malware file used in the attack is executed’).
- [T1218.005] System Binary Proxy Execution: Mshta – The malicious HTA script was executed through mshta to run attacker code (‘it launches Mshta with itself as an argument’).
- [T1059.001] Command and Scripting Interpreter: PowerShell – PowerShell scripts were used as droppers, downloaders, and uploaders (‘executes the PowerShell script’ and ‘obfuscated PowerShell commands’).
- [T1105] Ingress Tool Transfer – Additional payloads were downloaded from the C&C server and from attacker infrastructure (‘download and execute additional payloads’).
- [T1027] Obfuscated Files or Information – The downloader used obfuscated PowerShell commands to hide malicious intent (‘obfuscated PowerShell commands’).
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Templates.Js and Templates.Ps1 were created and registered as a task to persist execution (‘registers them as a task named “Windows Templates Update”‘).
- [T1053.005] Scheduled Task/Job: Scheduled Task – Persistence was established by creating a task named Windows Templates Update (‘registers them as a task named “Windows Templates Update”‘).
- [T1106] Native API – PebbleDash used system-level behavior to install itself and perform malicious actions based on received commands (‘can perform malicious behavior based on the commands received’).
- [T1003.001] OS Credential Dumping: LSASS Memory – The injector injected PebbleDash into LSASS to facilitate malicious activity (‘injects PebbleDash into the LSASS process’).
- [T1098] Account Manipulation – The attackers activated the administrator account and used backdoor accounts such as adminini (‘used to activate the “administrator” account’).
- [T1021.001] Remote Services: Remote Desktop Protocol – RDP was used for remote system control (‘used RDP to perform System Control’).
- [T1562.001] Impair Defenses: Disable or Modify Tools – The RDP patcher modified termsrv.dll to allow multiple sessions (‘replaces the “termsrv.Dll” file in the System32 directory with it’).
- [T1090] Proxy – PrxClient acted as a relay between the C&C server and local RDP ports (‘acts as a relay between the C&C server passed as an argument and a local port’).
- [T1548.002] Abuse Elevation Control Mechanism: Bypass User Account Control – UAC bypass tools such as UACMe and SspiUacBypass were used to elevate privileges (‘a tool that uses a technique to bypass UAC’).
- [T1056.001] Input Capture: Keylogging – The keylogger stored keystrokes and transmitted them to the C&C server (‘stores the user’s keystrokes’).
- [T1005] Data from Local System – The capture script read local files and transmitted them to the C&C server (‘reads files stored locally and transmits them’).
- [T1041] Exfiltration Over C2 Channel – Collected data and keystrokes were sent back through C&C communication (‘transmits them to the C&C server’).
- [T1071.001] Application Layer Protocol: Web Protocols – PebbleDash communicated with the server using URL-based web requests (‘Page=&mode=&DATA=’).
Indicators of Compromise
- [MD5 hashes] malware samples associated with the campaign – 00f27b3cf8817313aafdfc29ff238153, 029db651367bb1eac0a85bd826afe420, and 3 more hashes
- [URLs] payloads and support files hosted on attacker infrastructure – http[:]//167[.]88[.]165[.]122/login[.]asp, http[:]//edcvbgtrf[.]medianewsonline[.]com/1t32[.]exe, and 3 more items
- [FQDNs] command-and-control and download infrastructure – edcvbgtrf[.]medianewsonline[.]com, fsfhsfgsfsnxcvbasfsgsrhsf234fsd[.]mywebcommunity[.]org, and 3 more items
- [IP addresses] C&C and relay infrastructure used in the attacks – 103[.]212[.]120[.]253, 153[.]75[.]233[.]17, and 1 more item
- [File names] LNK, scripts, DLLs, and batch files used in infection and persistence – vvn.31.Pdf…………………………………………………………………………………………..Lnk, D.21 SEOUL.Lnk, and 2 more items
- [Registry key] PebbleDash configuration storage – HKLMSYSTEMCurrentControlSetControlWMISecurity / “CC1CFAFD-D1B4-4303-8C2C-0BC4E3C54B5C”
- [Mutex name] classification of the proxy tool – PrxClient identified by its mutex name
Read more: https://asec.ahnlab.com/en/94552/