North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-12-01 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37492
Kimsuky, also known as Black Banshee, is described as a North Korean state-sponsored APT active since at least 2012 and focused on espionage against targets in South Korea, Japan, the United States, and other countries. The advisory lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring tactics. It highlights Android malware activity involving FastFire, FastViewer, and FastSpy, including Firebase C2 use and modified Androspy code, and cites ReconShark as a BabyShark evolution used for reconnaissance and exfiltration. Representative indicators include spectacularfields.icu, b262ac518c0114f414aaedbb4ef7c728, and a defanged URL using the nood subdomain.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8e0eb0d36bfd4e28ec6a10acccf8997… | 2024-12-01 | 2024-12-05 |
| HASH | fd02470c6cc4ceb5fad3589d02e5148… | 2024-12-01 | 2024-12-05 |
| HASH | b262ac518c0114f414aaedbb4ef7c728 | 2024-12-01 | 2024-12-05 |
| DOMAIN | naverbox.p-e.kr | 2024-12-01 | 2024-12-02 |
| HASH | 31e683073959e206e072711fe2570271 | 2024-12-01 | 2024-12-01 |
| HASH | 2bfa1aaf1b6d52fcd7e120d74ba982c… | 2024-12-01 | 2024-12-01 |
| HASH | 7e47d1bc13d7016a9d8eb59a97d19e3… | 2024-12-01 | 2024-12-01 |
| DOMAIN | nbox.p-e.kr | 2024-12-01 | 2024-12-01 |