North Korean APT Kimsuky aka Black Banshee – Active IOCs

2025-03-17 Rewterz

https://rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-43

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Rewterz summarizes Kimsuky, also known as Black Banshee, as a North Korean APT active since at least 2012 and focused on espionage against targets including South Korea, Japan, and the United States. The advisory lists common tradecraft such as phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration, then highlights Android malware activity from 2022 involving FastFire, FastViewer, and FastSpy with Firebase-based C2 and Androspy-derived code. It also references ReconShark as a BabyShark evolution used for reconnaissance and information theft in later cyberespionage activity. The IOC section provides representative hashes and URLs for blocking and hunting, but the main value is the consolidated Kimsuky mobile and reconnaissance malware context.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5f23b1ca43f6a18e3c9f21d390f5d1e… 2025-03-17 2025-07-08
DOMAIN mrasis.n-e.kr 2025-03-17 2025-07-08
HASH 6ffb5106d912e582bde2c095365fa37… 2025-03-17 2025-06-19
IPv4 101.36.114.190 2025-03-17 2025-06-19
URL http://mrasis.n-e.kr/ 2025-03-17 2025-03-19
HASH 3cc47aea39c48aa22fbf246f11cd4aa… 2025-03-17 2025-03-17
HASH 784d5df037879ed47cf46f8b2ec2c54… 2025-03-17 2025-03-17

Related Actors

Related Reports

« Back