New North Korean Android spyware slips onto Google Play
ID: d8ebfb2c-456f-5f43-9baf-ae6811d7e1a2
STIX ID: report--d8ebfb2c-456f-5f43-9baf-ae6811d7e1a2
Feed Name: Bleeping Computer
Lookout researchers uncovered KoSpy, an Android spyware campaign attributed to North Korea’s APT37 that distributed at least five malicious apps on Google Play and APKPure posing as file managers, security utilities, and updaters; the spyware retrieves encrypted configs from Firebase, connects to C2 servers, evades emulators, and exfiltrates SMS/call logs, GPS, files, audio, camera captures, screenshots, and keystrokes. Google has removed the apps and corresponding Firebase projects, but infected users must manually uninstall and may require factory resets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
