lazarusholic

Everyday is lazarus.dayβ

North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-10-24, Rewterz
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-36924
#Kimsuky

Contents

Mirai Botnet aka Katana – Active IOCs
October 24, 2024APT28 FancyBear Group – Active IOCs
October 24, 2024Mirai Botnet aka Katana – Active IOCs
October 24, 2024APT28 FancyBear Group – Active IOCs
October 24, 2024Severity
High
Analysis Summary
Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". The group has been active since at least 2012 and is believed to be state-sponsored. Kimsuky is known for conducting cyber espionage operations and targeting organizations and individuals in various countries, including South Korea, Japan, and the United States. The group has been observed using various techniques to compromise its targets, such as phishing attacks, malware infections, and supply chain attacks. The group's ultimate goals and motivations are not well understood, but they are generally believed to be focused on intelligence gathering and political or economic gain. The tactics, techniques, and procedures (TTPs) used by the Kimsuky APT group are constantly evolving, but some …

IoC

6b9c1f4fff75be430f3e76c28d50493ab30e751e
95d13d6054d18f48328bc31e2eee68f7
3bc549b5b59a5f6f98d53bb9059667b8954b038641630fd68455155acbb25af7
154.90.62.152