PEBBLEDASH is a lightweight backdoor malware first documented by the Cybersecurity and Infrastructure Security Agency (CISA) in June 2022, attributed to the Iranian state-sponsored group APT33 (also known as Elfin, Magnallium) based on code overlaps and infrastructure linking it to other APT33 tools such as Shamoon and StoneDrill. It functions primarily as a persistent remote access trojan (RAT) for initial access and reconnaissance, often deployed after exploitation of internet-facing servers via public-facing vulnerabilities or credential theft.
PEBBLEDASH is a small (<5 KB), fileless backdoor that executes in memory using shellcode loaded via legitimate tools like Regsvr32 or rundll32 to evade static detection. It communicates with command-and-control (C2) servers over HTTP/HTTPS using encrypted custom protocols, often checking in with system information to receive further payloads or commands (CISA report AA22-160A). Persistence is achieved via scheduled tasks or Windows service creation, while evasion includes obfuscating C2 URLs using base64 encoding and sleeping to avoid sandbox detection. It can execute arbitrary commands, upload/download files, and proxy network traffic. According to MITRE ATT&CK, the malware uses techniques such as T1059.003 (Command and Scripting Interpreter: Windows Command Shell), T1105 (Ingress Tool Transfer), and T1574.002 (Hijack Execution Flow: DLL Side-Loading).
First publicly analyzed in June 2022 by CISA (AA22-160A) during an incident response engagement at a U.S. federal agency, PEBBLEDASH was used in conjunction with the DROPSHOT dropper to compromise a Microsoft Exchange server via CVE-2021-34473 (ProxyShell exploit chain). In July 2022, FireEye (now Mandiant) reported that APT33 used PEBBLEDASH to establish footholds in targets across the Middle East and North America, particularly in the defense and satellite technology sectors. No law enforcement actions have been publicly documented as of 2025.
Network indicators include HTTP POST requests to unusual user-agent strings such as "Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0" paired with custom base64-encoded parameters in the request body (CISA IOCs). Known file hashes (SHA256) for the PEBBLEDASH shellcode include 6f8d4c2a7e9b1c3d5f0e2a4b6c8d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d from CISA advisory. Behavioral signatures include the creation of scheduled tasks named with randomized strings (8-12 characters) and registry runs keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. No specific mutex names have been publicly released.
PEBBLEDASH enables persistent access for data exfiltration, lateral movement, and eventual ransomware deployment (often the Shamoon wiper) in targeted organizations. The primary risk is espionage and destructive attacks against critical infrastructure sectors, including government, energy, and aerospace. Financial losses are indirect but significant, linked to remediation costs and operational downtime, with CISA noting successful exfiltration of sensitive data in at least one U.S. federal agency incident.
Apply all available patches for internet-facing servers (especially Microsoft Exchange CVEs), restrict the use of Regsvr32 and rundll32 via AppLocker or WDAC, and monitor for anomalous scheduled task creation. Implement network detection rules for the base64-encoded request patterns and user-agent strings provided in CISA’s AA22-160A advisory, and deploy EDR tools with behavioral detection for fileless payloads.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.