logo

Spyware Masquerading As Banking App Targets Koreans

ID: 2e219579-2dcb-5966-961c-8d231ac44033

STIX ID: report--2e219579-2dcb-5966-961c-8d231ac44033

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-07-16

...
...

This report examines an Android spyware campaign that distributes a fake Woori Bank app via phishing pages targeting Korean users; the malware is packed and obfuscated, decrypts embedded DEX files using native libraries, performs anti-sandbox/emulator/root/VPN checks, abuses the Accessibility service to enable permissions, collects contacts, SMS, call logs, audio/video, location and screen content, and exfiltrates encrypted data to identified C2 servers. The analysis includes APK metadata, code excerpts, command mappings, persistence mechanisms, recommended mitigations, and a list of IoCs (SHA256 hashes, phishing URLs, and C2 IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.