North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-12-31 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37856
Kimsuky, also known as Black Banshee, is described as a North Korean APT active since at least 2012 and focused on espionage against targets in South Korea, Japan, the United States, and other countries. The advisory summarizes common Kimsuky tradecraft including phishing, malware deployment, supply chain compromise, lateral movement, and data exfiltration. It notes prior mobile operations using FastFire, FastViewer, and FastSpy Android malware with Firebase C2, plus ReconShark reconnaissance malware tied to BabyShark. The active IOC section lists domains including nts-service.o-r.kr and memconfirms.online for defensive blocking and hunting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | nts-service.o-r.kr | 2024-12-31 | 2024-12-31 |
| IPv4 | 72.14.155.62 | 2024-12-05 | 2024-12-31 |