logo

New North Korean Android spyware slips onto Google Play

ID: d8ebfb2c-456f-5f43-9baf-ae6811d7e1a2

STIX ID: report--d8ebfb2c-456f-5f43-9baf-ae6811d7e1a2

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-03-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Lookout researchers uncovered KoSpy, an Android spyware campaign attributed to North Korea’s APT37 that distributed at least five malicious apps on Google Play and APKPure posing as file managers, security utilities, and updaters; the spyware retrieves encrypted configs from Firebase, connects to C2 servers, evades emulators, and exfiltrates SMS/call logs, GPS, files, audio, camera captures, screenshots, and keystrokes. Google has removed the apps and corresponding Firebase projects, but infected users must manually uninstall and may require factory resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.