North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-11-01 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37051
Kimsuky, also called Black Banshee in the advisory, is described as a North Korean espionage group active since at least 2012 and targeting organizations and individuals in South Korea, Japan, and the United States. The source lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring TTPs. It highlights Android targeting in 2022 through FastFire, FastViewer, and FastSpy, including use of Firebase for command and control and Androspy based modifications to steal device information from South Korean targets. The advisory also notes ReconShark, an evolution of BabyShark, as reconnaissance malware used in a 2023 global cyberespionage campaign, with radiofreeasia.blog and several hashes provided as IOCs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 67495e04457f66065470ab96c88d55e… | 2024-11-01 | 2024-11-01 |
| HASH | ae4dc41b8f5664b5aef5d82be55624d… | 2024-11-01 | 2024-11-01 |
| HASH | f1b542971711bf229d02f5e385225a8d | 2024-09-05 | 2024-11-01 |
| IPv4 | 79.133.56.173 | 2024-09-05 | 2024-11-01 |