Kimsuky targets organizations with PebbleDash-based tools
2026-05-15T20:52:25Z•34a282f32cc30086e17905706a26a5dc4f809b70427df3fbf783c33d36703e27
ABCDoorAmazon SES phishingAppleSeedBECCVE-2025-68670EDR-killersFakeWalletKimsukyOceanLotusPebbleDashPhantomRPCPyPI supply chainQ1 2026RCESilver FoxValleyRATWindows RPCZiChatBotdata-leak extortioniOS App Storeprivilege escalationransomware trendsvulnerabilities and exploitsxrdp
What happened
Kaspersky Securelist (May 2026) highlights multiple high-risk campaigns and vulnerabilities: Kimsuky using new PebbleDash-based tools linked to the AppleSeed cluster; OceanLotus distributing ZiChatBot via malicious PyPI wheels; Silver Fox deploying ValleyRAT and a new ABCDoor backdoor via tax-notification lures; and FakeWallet crypto-stealers found in App Store iOS apps. It also documents broader trends—ransomware shifting toward data leaks and EDR-killers, Amazon SES being abused for phishing/BEC, and statistical coverage of Q1 2026 exploits/C2 usage. Notable vulnerabilities disclosed include
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 34a282f32cc30086e17905706a26a5dc4f809b70427df3fbf783c33d36703e27
- Enrichment time
- 2026-05-15T20:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.