logo

Kimsuky Hackers Attacking Users via Weaponized QR Code to Deliver Malicious Mobile App

ID: a80b8ff4-4bd6-5a88-9f2c-0a331eace0af

STIX ID: report--a80b8ff4-4bd6-5a88-9f2c-0a331eace0af

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Kimsuky has deployed an evolved DOCSWAP Android malware variant in a QR-code-based smishing campaign that lures victims to fake delivery/tracking sites. The APK (SecDelivery.apk) contains an encrypted payload decrypted by a native library (libnative-lib.so) and registers a persistent service (MainService) triggered on boot and power events; it supports 57 RAT commands for audio/video capture, file management, location and call/SMS exfiltration, and Accessibility-based keylogging. Researchers tied the campaign to prior Kimsuky operations via shared infrastructure and artifacts including a C2 at 27.102.137.181 and Korean-language indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.