INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PebbleDash-based Malware Targets Organizations

| 2026-05-14 11:00 CRITICAL HIGH
Executive Summary AI-generated
Kimsuky's AppleSeed and PebbleDash malware clusters have been targeting various sectors in South Korea, including public and private entities, with a focus on government organizations. The groups' interest extends to defense, military, medical, and energy industries worldwide. These attacks often disguise themselves as legitimate sites or products, using digital certificates for authenticity. The threat actors continue to evolve their tactics, making analysis of malware clusters like AppleSeed and PebbleDash crucial in grasping the evolving nature of cyber threats.
Technical Mitigations AI-generated
• Use legitimate VSCode authentication methods, such as GitHub authentication. • Utilize DWAgent for remote monitoring and management of post-exploitation activities. • Employ a variety of droppers in different formats, including JSE, PIF, SCR, EXE, etc., from the PebbleDash cluster.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
KimsukyKimsukyLazarus GroupLazarus Group BabySharkBabySharkTroll StealerTroll StealerAppleSeedAppleSeed
Target & Sectors
DACH DACH defensedefense governmentgovernment energyenergy
Incident Timeline
‎at least 2019
Threat actors used custom-made PebbleDash-based tools to target organizations since at least 2019 by masquerading as legitimate documents and application installers.
‎2025/05/14
Threat actors used the JSE dropper to target Visual Studio Code.
threat_actor Kimsuky
infrastructure Visual Studio Code
organisation Darktrace
‎early 2025
Threat actors used the httpMalice command to target organizations with PebbleDash-based tools.
general_metric 8 .
general_metric 3 security_20260126.scr
infrastructure 0 Command Description
infrastructure 2 encoding Download
infrastructure 5 server
general_metric 6 directory
general_metric 7 current directory
general_metric 9 Hibernate
general_metric 10 Hibernate
general_metric 12 ID
general_metric 13 Load
‎August 28, 2025
Threat actors used a PebbleDash-based tool to target organizations with Kimsuky malware.
observable hwpx.jse
observable hwp.jse
observable 995a0a49ae4b244928b3f67e2bfd7a6e
observable 52f1ff082e981cbdfd1f045c6021c63f
tactic T1588.001 - Malware
general_metric 1 Malware
general_metric 8 .
general_metric 3 security_20260126.scr
‎August 2025
Kimsuky used the "msleep" command to sleep for a specified time.
threat_actor Kimsuky
organisation DLL
infrastructure Windows
organisation Register
organisation MAC
organisation TryCloudflare
organisation Cloudflare
organisation LLM
‎December 14, 2025
Threat actors used a PebbleDash-based tool to target organizations with the HelloDoor malware.
observable hwpx.jse
observable hwp.jse
observable 995a0a49ae4b244928b3f67e2bfd7a6e
observable 52f1ff082e981cbdfd1f045c6021c63f
tactic T1588.001 - Malware
general_metric 1 Malware
general_metric 8 .
general_metric 3 security_20260126.scr
‎no later than December 2025
The JSE Dropper, a known PebbleDash-based backdoor, was used to target organizations as early as no later than December 2025.
‎December 2025
The incident involves the use of a Reger Dropper and HappyDoor malware by Kimsuky to target organizations with PebbleDash-based tools.
threat_actor Kimsuky
organisation GPKI
infrastructure Windows
infrastructure 3.0
organisation a7f0a18ac87e982d6f32f7a715e12532
organisation f4465403f9693939fe9c439f0ab33610
organisation 서류.hwpx.jse
organisation VSCode Tunnel
organisation IPs
organisation hxxp://newjo-imd[.]com
organisation HappyDoor HappyDoor
organisation backdoor malware
organisation AhnLab
organisation RSA
organisation InterServer
infrastructure Visual Studio Code
organisation CLI
organisation File
infrastructure 0 Command Description
infrastructure 1 type Download source
organisation POST
infrastructure 2.1
infrastructure 1.9
infrastructure 1.8
organisation Dropbox
organisation /c chcp 949
infrastructure 1.106.3
infrastructure 1.106.2
organisation Installer
organisation ZIP
organisation SID
financial 12288 S-1 SID
organisation API
organisation IP
organisation UID
organisation ChromeCheck
organisation JSE Dropper
organisation Spy
organisation USB
organisation DWAgent
organisation Microsoft
organisation GitHub
organisation the VSCode CLI
organisation Microsoft Account
organisation VSCode CLI
organisation Slack
organisation the Reger Dropper
organisation Target
‎January 26, 2026
Threat actors used security_20260126.scr to target individuals and organizations with PebbleDash-based tools.
observable hwpx.jse
observable hwp.jse
observable 995a0a49ae4b244928b3f67e2bfd7a6e
observable 52f1ff082e981cbdfd1f045c6021c63f
tactic T1588.001 - Malware
general_metric 1 Malware
general_metric 8 .
general_metric 3 security_20260126.scr
‎January 28, 2026
Threat actors used Pidoc Dropper and HappyDoor to target AppleSeed chain.
malware AppleSeed
observable pdf.jse
observable 노현정님.pdf
observable Hyun-jung.pdf
observable 8e15c4d4f71bdd9dbc48cd2cabc87806
observable 65fc9f06de5603e2c1af9b4f288bb22c
observable 8983ffa6da23e0b99ccc58c17b9788c7
organisation MemLoad
organisation the Public Service Management System
general_metric 4 노현정님.pdf.jse
general_metric 5 대국민서비스관리운영체계현장점검증적(초안).pif Inspection Evidence
‎February 5, 2026
The malware targets organizations using PebbleDash-based tools, ultimately executing the malicious payload via command-line instructions such as regsvr32.exe /s 65fc9f06de5603e2c1af9b4f288bb22c.
malware AppleSeed
observable pdf.jse
observable 노현정님.pdf
observable Hyun-jung.pdf
observable 8e15c4d4f71bdd9dbc48cd2cabc87806
observable 65fc9f06de5603e2c1af9b4f288bb22c
observable 8983ffa6da23e0b99ccc58c17b9788c7
organisation MemLoad
organisation the Public Service Management System
general_metric 4 노현정님.pdf.jse
general_metric 5 대국민서비스관리운영체계현장점검증적(초안).pif Inspection Evidence
threat_actor Kimsuky
organisation JScript
organisation XOR
organisation Pidoc Dropper
organisation Deployed
‎2026/05/14
Kimsuky targets organizations with PebbleDash-based tools.
threat_actor Kimsuky
organisation RandomQuery
organisation TutRAT
infrastructure Visual Studio Code
organisation PebbleDash
organisation Black Banshee
threat_actor Lazarus Group
organisation Specifically,
organisation VSCode
organisation JSE
organisation PIF
organisation SCR
organisation EXE
organisation Kaspersky
organisation APT
organisation VSCode Tunneling
organisation Cloudflare Quick Tunnels
organisation HelloDoor
Tactical Metrics
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎1.9
Software Version
Metrics
infrastructure
‎1.8
Software Version
Metrics
infrastructure
‎3.0
Software Version
Metrics
infrastructure
‎2.1
Software Version
Metrics
infrastructure
‎1.106.3
Software Version
Metrics
infrastructure
‎1.106.2
Software Version
Metrics
infrastructure
1
Type Download Source
Metrics
financial
12,288
S-1 Sid
Metrics
infrastructure
0
Command Description
Metrics
infrastructure
2
Encoding Download
Metrics
infrastructure
5
Server
Intelligence Sources