PEBBLEDASH

First seen
2020-04-01 00:00:00
Malware type
backdoor, rat
Profile updated
2026-07-07 14:21:03

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:gb

Context

PEBBLEDASH is a sophisticated remote access tool (RAT) used by state-sponsored threat actors for espionage purposes. It primarily targets government and defense sectors, providing backdoor capabilities for data exfiltration and persistence.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Pebbledash_Auto (yara-rule)

Reports & references

  • asec.ahnlab.com — 59590 (report)
  • asec.ahnlab.com — 30532 (report)
  • asec.ahnlab.com — Kimsuky %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Apt %Ea%B3%B5%Ea%B2%A9 %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C Appleseed Pebbledash (report)
  • download.ahnlab.com — Analysis%20Report%20Of%20Kimsuky%20Group (report)
  • asec.ahnlab.com — 87621 (report)
  • blog.reversinglabs.com — Hidden Cobra (report)
  • Kaspersky — 102811 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pebbledash (report)
  • verfassungsschutz.de — 2024 02 19 Joint Cyber Security Advisory Englisch (report)
  • malwarenailed.blogspot.com — Peebledash Lazarus Hiddencobra Rat (report)
  • asec.ahnlab.com — 30022 (report)
  • us-cert.gov — Ar20 133C (report)

External references