← Back to Feed
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
July 16, 2026 · AhnLab ASEC · Severity: HIGH
This article reports on ongoing attack campaigns by the Kimsuky threat actor, who impersonates diplomats to deliver PebbleDash and PrxClient malware via spear phishing. The group has been active in 2026, continuing their malicious activities.
Key Takeaways
- Kimsuky group continues spear phishing attacks impersonating diplomats.
- Malware used includes PebbleDash and PrxClient.
- Attacks persist into 2026 with updated tactics.