North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-12-16 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37627
Rewterz profiles Kimsuky, also called Black Banshee, as a North Korea-linked APT active since at least 2012 and focused on cyber espionage against targets in South Korea, Japan, the United States, and other countries. The advisory describes recurring phishing, malware infections, supply-chain compromise, lateral movement, and data exfiltration, with RATs, backdoors, and wipers among the cited malware types. It also notes Android activity using FastFire, FastViewer, and FastSpy, Firebase as C2 for FastFire, Androspy modifications, ReconShark/BabyShark reconnaissance malware, and IOCs including delps.scienceontheweb.net and several hashes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1e05449bccfeb965985c356f3ea88787 | 2024-12-16 | 2024-12-16 |
| HASH | 035569bdbf955493e4bf5045610fa66… | 2024-12-16 | 2024-12-16 |
| HASH | 3c79940610603c0420aa3bf904ff92bf | 2024-12-16 | 2024-12-16 |
| HASH | 037ee4de3892fbf7ba1929ae64f0ee6… | 2024-12-16 | 2024-12-16 |
| HASH | 2e40620da710d81d4d1d95d1694aa82… | 2024-12-16 | 2024-12-16 |
| HASH | c19df37c6d819dae3cc2628940bd352… | 2024-12-16 | 2024-12-16 |
| DOMAIN | safeblog.o-r.kr | 2024-12-16 | 2024-12-16 |
| DOMAIN | delps.scienceontheweb.net | 2023-03-17 | 2024-12-16 |