North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-12-01 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37492

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Kimsuky, also known as Black Banshee, is described as a North Korean state-sponsored APT active since at least 2012 and focused on espionage against targets in South Korea, Japan, the United States, and other countries. The advisory lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring tactics. It highlights Android malware activity involving FastFire, FastViewer, and FastSpy, including Firebase C2 use and modified Androspy code, and cites ReconShark as a BabyShark evolution used for reconnaissance and exfiltration. Representative indicators include spectacularfields.icu, b262ac518c0114f414aaedbb4ef7c728, and a defanged URL using the nood subdomain.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8e0eb0d36bfd4e28ec6a10acccf8997… 2024-12-01 2024-12-05
DOMAIN naverbox.p-e.kr 2024-12-01 2024-12-02
HASH 2bfa1aaf1b6d52fcd7e120d74ba982c… 2024-12-01 2024-12-01
DOMAIN nbox.p-e.kr 2024-12-01 2024-12-01

Related Actors

Related Reports

« Back