North Korean APT Kimsuky aka Black Banshee – Active IOCs

2025-04-18 Rewterz

https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-45

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Rewterz profiles Kimsuky, also tracked as Black Banshee, as a North Korean espionage group using phishing, malware infections, supply-chain compromise, lateral movement, and data exfiltration against targets in South Korea, Japan, the United States, and other regions. The source ties earlier mobile operations to FastFire, FastViewer, and FastSpy Android malware that used Firebase as command-and-control infrastructure and targeted South Korean users. It also notes ReconShark, an evolution of BabyShark, as reconnaissance malware used in a global cyberespionage campaign. The advisory provides active hash and network indicators, including holosformations.fr and 103.149.98.247 URLs, for defensive blocking and hunting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 42f306b905ece8875bdf16d276b8e4c… 2025-04-18 2025-07-01
IPv4 103.149.98.247 2025-04-18 2025-07-01
HASH 869705fd4dd777d4ab5c662806b42fe… 2025-04-18 2025-05-19
HASH 7bed4de469d5f23f35f835d6bf1b767… 2025-04-18 2025-04-18
URL https://www.holosformations.fr/… 2025-04-18 2025-04-18

Related Actors

Related Reports

« Back