PEBBLEDASH
- First seen
- 2020-04-01 00:00:00
- Malware type
- backdoor, rat
- Profile updated
- 2026-07-07 14:21:03
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:us country_code:gb
Context
PEBBLEDASH is a sophisticated remote access tool (RAT) used by state-sponsored threat actors for espionage purposes. It primarily targets government and defense sectors, providing backdoor capabilities for data exfiltration and persistence.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Pebbledash_Auto (yara-rule)
Reports & references
- asec.ahnlab.com — 59590 (report)
- asec.ahnlab.com — 30532 (report)
- asec.ahnlab.com — Kimsuky %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Apt %Ea%B3%B5%Ea%B2%A9 %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C Appleseed Pebbledash (report)
- download.ahnlab.com — Analysis%20Report%20Of%20Kimsuky%20Group (report)
- asec.ahnlab.com — 87621 (report)
- blog.reversinglabs.com — Hidden Cobra (report)
- Kaspersky — 102811 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pebbledash (report)
- verfassungsschutz.de — 2024 02 19 Joint Cyber Security Advisory Englisch (report)
- malwarenailed.blogspot.com — Peebledash Lazarus Hiddencobra Rat (report)
- asec.ahnlab.com — 30022 (report)
- us-cert.gov — Ar20 133C (report)