lazarusholic

Everyday is lazarus.dayβ

North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-11-01, Rewterz
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37051
#Kimsuky

Contents

APT37 aka ScarCruft or RedEyes – Active IOCs
November 1, 2024LiteSpeed Cache Plugin Vulnerability Puts WordPress Websites at Serious Risk
November 1, 2024APT37 aka ScarCruft or RedEyes – Active IOCs
November 1, 2024LiteSpeed Cache Plugin Vulnerability Puts WordPress Websites at Serious Risk
November 1, 2024Severity
High
Analysis Summary
Kimsuky is a North Korean advanced persistent threat (APT) group, also known as "Black Banshee". The group has been active since at least 2012 and is believed to be state-sponsored. Kimsuky is known for conducting cyber espionage operations and targeting organizations and individuals in various countries, including South Korea, Japan, and the United States. The group has been observed using various techniques to compromise its targets, such as phishing attacks, malware infections, and supply chain attacks. The group's ultimate goals and motivations are not well understood, but they are generally believed to be focused on intelligence gathering and political or economic gain. The tactics, techniques, and procedures (TTPs) used …

IoC

ae4dc41b8f5664b5aef5d82be55624d53be4ead0a23b029ae290e02c8d5f9e4f
67495e04457f66065470ab96c88d55e4ec3bf51e
79.133.56.173
f1b542971711bf229d02f5e385225a8d