Kimsuky__2020__VB2020-46.pdf
ID: 7dc2f81c-3d37-4be5-90db-f603f63f3ed8
STIX ID: report--7dc2f81c-3d37-4be5-90db-f603f63f3ed8
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2020-09-04
Last Modified Date: 2020-09-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
PwC's "To catch a Banshee" report profiles the North Korea-linked APT Kimsuky (aka Black Banshee), documenting its evolution and multiple concurrent espionage campaigns from 2018–2020. The presentation catalogs malware families (BabyShark, AppleSeed, FlowerPower, GoldDragon, WildCommand), encoding/packing/host patterns, C2 URL structures and server-side scripts, observed IPs/domains, timelines, and strategic targeting (South Korea, Japan, US policy, supranational bodies), providing technical IoCs and tradecraft indicators useful for detection and hunting.
