North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-12-16 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37627

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Rewterz profiles Kimsuky, also called Black Banshee, as a North Korea-linked APT active since at least 2012 and focused on cyber espionage against targets in South Korea, Japan, the United States, and other countries. The advisory describes recurring phishing, malware infections, supply-chain compromise, lateral movement, and data exfiltration, with RATs, backdoors, and wipers among the cited malware types. It also notes Android activity using FastFire, FastViewer, and FastSpy, Firebase as C2 for FastFire, Androspy modifications, ReconShark/BabyShark reconnaissance malware, and IOCs including delps.scienceontheweb.net and several hashes.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1e05449bccfeb965985c356f3ea88787 2024-12-16 2024-12-16
HASH 035569bdbf955493e4bf5045610fa66… 2024-12-16 2024-12-16
HASH 3c79940610603c0420aa3bf904ff92bf 2024-12-16 2024-12-16
HASH 037ee4de3892fbf7ba1929ae64f0ee6… 2024-12-16 2024-12-16
HASH 2e40620da710d81d4d1d95d1694aa82… 2024-12-16 2024-12-16
HASH c19df37c6d819dae3cc2628940bd352… 2024-12-16 2024-12-16
DOMAIN safeblog.o-r.kr 2024-12-16 2024-12-16
DOMAIN delps.scienceontheweb.net 2023-03-17 2024-12-16

Related Actors

Related Reports

« Back