logo

Fake Android and iOS apps steal SMS and contacts in South Korea

ID: 4e9f5188-9baf-564d-9bbd-91b500029e99

STIX ID: report--4e9f5188-9baf-564d-9bbd-91b500029e99

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2023-11-15

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research discovered an active phishing campaign targeting South Korea that distributes Android and iOS information-stealers disguised as legitimate apps (e.g., social, photo storage, fitness). Attackers engage victims via SMS and LINE, lure them to phishing sites that serve sideloaded APK/IPA files (bypassing official app stores), and steal sensitive data including phone numbers, contacts, and SMS messages; the report includes multiple phishing URLs, C2 domains, and SHA256 hashes for malicious binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.