North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-12-01 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37492

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Kimsuky, also known as Black Banshee, is described as a North Korean state-sponsored APT active since at least 2012 and focused on espionage against targets in South Korea, Japan, the United States, and other countries. The advisory lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring tactics. It highlights Android malware activity involving FastFire, FastViewer, and FastSpy, including Firebase C2 use and modified Androspy code, and cites ReconShark as a BabyShark evolution used for reconnaissance and exfiltration. Representative indicators include spectacularfields.icu, b262ac518c0114f414aaedbb4ef7c728, and a defanged URL using the nood subdomain.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8e0eb0d36bfd4e28ec6a10acccf8997… 2024-12-01 2024-12-05
HASH fd02470c6cc4ceb5fad3589d02e5148… 2024-12-01 2024-12-05
HASH b262ac518c0114f414aaedbb4ef7c728 2024-12-01 2024-12-05
DOMAIN naverbox.p-e.kr 2024-12-01 2024-12-02
HASH 31e683073959e206e072711fe2570271 2024-12-01 2024-12-01
HASH 2bfa1aaf1b6d52fcd7e120d74ba982c… 2024-12-01 2024-12-01
HASH 7e47d1bc13d7016a9d8eb59a97d19e3… 2024-12-01 2024-12-01
DOMAIN nbox.p-e.kr 2024-12-01 2024-12-01

Related Actors

Related Reports

« Back