threat-intel
Kimsuky targets organizations with PebbleDash-based tools
High
Summary
This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolved its tactics, incorporating advanced tools like VSCode Tunneling, LLMs, and the Rust programming language, alongside established techniques like spear-phishing. Kimsuky’s campaigns primarily target organizations in South Korea, Brazil, and Germany, focusing on sectors including defense and government, and have been active for over a decade.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
