logo

Kimsuky__2020__VB2020-46.pdf

ID: 7dc2f81c-3d37-4be5-90db-f603f63f3ed8

STIX ID: report--7dc2f81c-3d37-4be5-90db-f603f63f3ed8

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2020-09-04

Last Modified Date: 2020-09-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
PwC's "To catch a Banshee" report profiles the North Korea-linked APT Kimsuky (aka Black Banshee), documenting its evolution and multiple concurrent espionage campaigns from 2018–2020. The presentation catalogs malware families (BabyShark, AppleSeed, FlowerPower, GoldDragon, WildCommand), encoding/packing/host patterns, C2 URL structures and server-side scripts, observed IPs/domains, timelines, and strategic targeting (South Korea, Japan, US policy, supranational bodies), providing technical IoCs and tradecraft indicators useful for detection and hunting.