Kimsuky targets organizations with PebbleDash-based tools

2026-05-17T08:51:55Z632870e5b61d7024ffaae64bc7b0021d9532f82f027e725d5f62cf881609dd4b
ABCDoorAmazon SESApp StoreAppleSeedCVE-2025-68670EDR evasionFakeWalletKimsukyOceanLotusPebbleDashPhantomRPCPyPISilver FoxValleyRATZiChatBotiOSphishingpre-auth RCEprivilege escalationransomwaresupply-chainvulnerability reportxrdp

What happened

Kaspersky published multiple May 2026 intelligence briefs: researchers link Kimsuky campaigns to AppleSeed and document new PebbleDash-based tooling; detail OceanLotus PyPI supply-chain drops (ZiChatBot) affecting Windows and Linux; report a pre-auth RCE in xrdp (CVE-2025-68670, patched) discovered during assessment of Kaspersky USB Redirector; describe Silver Fox tax‑notification lures delivering ValleyRAT and a new ABCDoor backdoor; disclose PhantomRPC, a Windows RPC privilege‑escalation technique; and highlight trends in ransomware (EDR killers, data‑leak focus), Amazon SES‑based phishing/B

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
632870e5b61d7024ffaae64bc7b0021d9532f82f027e725d5f62cf881609dd4b
Enrichment time
2026-05-17T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.