North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-11-19 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37323
Kimsuky, also known as Black Banshee, is described as a North Korean APT that conducts espionage against organizations and individuals in South Korea, Japan, the United States, and other countries. The advisory summarizes recurring tradecraft including phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration. It calls out Android malware operations using FastFire, FastViewer, and FastSpy, with Firebase used as C2 in FastFire and modified Androspy code used to avoid detection. The source also references ReconShark reconnaissance malware and provides indicators such as 548c04abddb39c52136d29cf54921fa3 and two bit-albania.com URLs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | bit-albania.com | 2023-08-01 | 2025-07-01 |
| HASH | 315d3f8ead6f173261c06c04b385737… | 2024-11-19 | 2024-11-19 |
| HASH | 548c04abddb39c52136d29cf54921fa3 | 2024-11-19 | 2024-11-19 |
| HASH | d11b41aee220b451393598677d7e62b… | 2024-11-19 | 2024-11-19 |
| URL | https://bit-albania.com/templat… | 2024-11-19 | 2024-11-19 |
| URL | https://bit-albania.com/templat… | 2024-11-19 | 2024-11-19 |