logo

Android malware targeting South Korean mobile users

ID: 775fd6c1-811b-5753-9167-b23ab3b9c041

STIX ID: report--775fd6c1-811b-5753-9167-b23ab3b9c041

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A ThreatLabZ analysis describes a malicious Android application masquerading as AhnLab's V3 Mobile Plus that targets South Korean bank users: it requests device administrator privileges, hides its icon, runs background services to steal SMS messages and NPKI authentication certificates, and exfiltrates this data to a command-and-control server; the report includes technical indicators, screenshots, and removal/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.