North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-10-24 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-36924

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Kimsuky, also called Black Banshee in the advisory, is described as a North Korean espionage group active since at least 2012 and focused on organizations and individuals in South Korea, Japan, and the United States. The source lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as common methods. It highlights Android targeting in 2022 through FastFire, FastViewer, and FastSpy, including Firebase based command and control, Androspy derived code, and attacks against South Korean users. The advisory also cites ReconShark, an evolution of BabyShark, as reconnaissance malware used in a 2023 global cyberespionage campaign, with hashes such as 95d13d6054d18f48328bc31e2eee68f7 and 3bc549b5b59a5f6f98d53bb9059667b8954b038641630fd68455155acbb25af7 listed as IOCs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 95d13d6054d18f48328bc31e2eee68f7 2024-10-24 2024-10-24
HASH 3bc549b5b59a5f6f98d53bb9059667b… 2024-10-24 2024-10-24
HASH 6b9c1f4fff75be430f3e76c28d50493… 2024-10-24 2024-10-24
IPv4 154.90.62.152 2024-10-24 2024-10-24

Related Actors

Related Reports

« Back