Black Banshee
2020-02-18 • PWC • Tracking ‘Kimsuky’, the North Korea-based cyber e…
Black Banshee is PwC's tracking name for the North Korea-based cyber espionage group more widely known as Kimsuky. PwC's 2019-2020 analysis grouped the group's operations into interlinked activity clusters connected by shared infrastructure, tooling, and tradecraft rather than isolated campaigns. One cluster traced a continuous effort from earlier publicly reported operations through a remote access trojan PwC called WildCommand, targeting the South Korean government, aerospace and defense contractors, and cryptocurrency organizations, before resurfacing against financial-sector entities in South East Asia. A second cluster, known elsewhere as BabyShark, persistently targeted policy and national-security think tanks and government bodies in the United States, South Korea, and Europe, and was assessed to continue in later reporting under different public names. The group also ran credential-harvesting operations against government departments and, separately, against a United Nations human-rights body, and introduced additional malware families over time. PwC assessed that Black Banshee's tradecraft, infrastructure reuse, and consistent targeting reflected a coordinated, strategically driven espionage mission that showed no signs of slowing.
-
43
Related Actors
-
799
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Black Banshee reports only