Tracking ‘Kimsuky’, the North Korea-based cyber espionage group: Part 1

2020-02-18 PWC

https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/tracking-kimsuky-north-korea-based-cyber-espionage-group-part-1.html

Thumbnail for Tracking ‘Kimsuky’, the North Korea-based cyber espionage group: Part 1

PwC describes Black Banshee, also known as Kimsuky, as a North Korea-based espionage actor that ran multiple 2019 campaigns spanning broad credential harvesting, spear-phishing, targeted espionage, and data exfiltration. The report focuses on infrastructure tradecraft: domains impersonating government, academic, and policy organisations; C2 domains resolving into the 185.224.137[.]0/23 and 185.224.138[.]0/23 ranges; and repeated use of 185.224.137[.]164 across at least 24 malicious domains. It also notes kakao-check[.]esy[.]es as C2 for MyDogs, a RAT associated with Black Banshee, and highlights recurring parent domains, adversary-registered naming patterns, and server-side folder conventions. These shared infrastructure habits allowed PwC to connect otherwise separate 2019 Black Banshee campaign clusters and prepare a follow-on analysis of their targeting, tradecraft, and objectives.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 185.224.137.164 2020-02-18 2020-11-12

Related Actors

Related Reports

« Back