North Korean APT Kimsuky aka Black Banshee – Active IOCs
2024-11-08 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korean-apt-kimsuky-aka-black-banshee-active-iocs-37159
Rewterz describes Kimsuky, also called Black Banshee, as a North Korean APT active since at least 2012 and focused on espionage against organizations and individuals in South Korea, Japan, the United States, and other countries. The source lists phishing, malware infections, supply chain compromise, lateral movement, and data exfiltration as recurring Kimsuky tradecraft. It also references the group's Android malware activity using FastFire, FastViewer, and FastSpy, and its ReconShark reconnaissance malware derived from BabyShark. The active indicators include treffic.medianewsonline[.]com, partybbq.co[.]kr upload infrastructure, and multiple hash values tied to the advisory.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e13ad0ebaac36ec363eba5760e69cb9… | 2024-11-08 | 2024-11-13 |
| HASH | b7de564386ab778046b1dd3ef76e4b5e | 2024-11-08 | 2024-11-13 |
| HASH | baa69876baa6861db5736c58d2eded9… | 2024-11-08 | 2024-11-13 |
| URL | http://partybbq.co.kr/src/bbs/c… | 2023-08-28 | 2024-11-13 |
| DOMAIN | partybbq.co.kr | 2023-05-24 | 2024-11-13 |
| HASH | fdb058193917718fae6703e3090b8536 | 2024-11-08 | 2024-11-08 |
| HASH | 6d84e311cf0d5ed3c6ab05d50d61d3e… | 2024-11-08 | 2024-11-08 |
| HASH | be9b79d09ba059caf88d6512f51be52… | 2024-11-08 | 2024-11-08 |
| DOMAIN | treffic.medianewsonline.com | 2024-11-08 | 2024-11-08 |