North Korean APT Kimsuky aka Black Banshee – Active IOCs

2024-11-08 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37159

Thumbnail for North Korean APT Kimsuky aka Black Banshee – Active IOCs

Rewterz describes Kimsuky, also called Black Banshee, as a North Korean APT active since at least 2012 and focused on espionage against organizations and individuals in South Korea, Japan, the United States, and other countries. The source lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring Kimsuky tradecraft. It also references the group's Android malware activity using FastFire, FastViewer, and FastSpy, and its ReconShark reconnaissance malware derived from BabyShark. The active indicators include treffic.medianewsonline[.]com, partybbq.co[.]kr upload infrastructure, and multiple hash values tied to the advisory.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e13ad0ebaac36ec363eba5760e69cb9… 2024-11-08 2024-11-13
HASH b7de564386ab778046b1dd3ef76e4b5e 2024-11-08 2024-11-13
HASH baa69876baa6861db5736c58d2eded9… 2024-11-08 2024-11-13
URL http://partybbq.co.kr/src/bbs/c… 2023-08-28 2024-11-13
DOMAIN partybbq.co.kr 2023-05-24 2024-11-13
HASH fdb058193917718fae6703e3090b8536 2024-11-08 2024-11-08
HASH 6d84e311cf0d5ed3c6ab05d50d61d3e… 2024-11-08 2024-11-08
HASH be9b79d09ba059caf88d6512f51be52… 2024-11-08 2024-11-08
DOMAIN treffic.medianewsonline.com 2024-11-08 2024-11-08

Related Actors

Related Reports

« Back