logo

APT37 hackers abuse Google Find Hub in Android data-wiping attacks

ID: 451b9f7a-cde5-5bec-b192-9fdb1ef4b246

STIX ID: report--451b9f7a-cde5-5bec-b192-9fdb1ef4b246

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-11-11

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Genians attributes a KONNI campaign tied to North Korean actors (overlapping with APT37/Kimsuky) that uses KakaoTalk spear-phishing to deliver signed MSI/ZIP installers which deploy KONNI and secondary RATs (Remcos, Quasar, RftRAT) to exfiltrate credentials and then abuse Google Find Hub to GPS-locate and remotely factory-reset Android devices, preventing recovery and allowing the attackers to propagate via compromised KakaoTalk PC sessions; the report provides technical analysis, IoCs, and recommends MFA and rapid account recovery measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.