Kimsuky targets organizations with PebbleDash-based tools
2026-05-17T08:51:55Z•632870e5b61d7024ffaae64bc7b0021d9532f82f027e725d5f62cf881609dd4b
ABCDoorAmazon SESApp StoreAppleSeedCVE-2025-68670EDR evasionFakeWalletKimsukyOceanLotusPebbleDashPhantomRPCPyPISilver FoxValleyRATZiChatBotiOSphishingpre-auth RCEprivilege escalationransomwaresupply-chainvulnerability reportxrdp
What happened
Kaspersky published multiple May 2026 intelligence briefs: researchers link Kimsuky campaigns to AppleSeed and document new PebbleDash-based tooling; detail OceanLotus PyPI supply-chain drops (ZiChatBot) affecting Windows and Linux; report a pre-auth RCE in xrdp (CVE-2025-68670, patched) discovered during assessment of Kaspersky USB Redirector; describe Silver Fox tax‑notification lures delivering ValleyRAT and a new ABCDoor backdoor; disclose PhantomRPC, a Windows RPC privilege‑escalation technique; and highlight trends in ransomware (EDR killers, data‑leak focus), Amazon SES‑based phishing/B
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 632870e5b61d7024ffaae64bc7b0021d9532f82f027e725d5f62cf881609dd4b
- Enrichment time
- 2026-05-17T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.