Android Spyware Targeting Users In South Korea
ID: 3c6d0910-805a-5554-938b-8a81df073fbb
STIX ID: report--3c6d0910-805a-5554-938b-8a81df073fbb
Feed Name: Cyble Blog
Threat Score
**Executive Summary:** A previously undetected Android spyware campaign active since June 2024 targets individuals in South Korea by distributing malicious APKs that request minimal permissions (READ_SMS, READ_CONTACTS, READ_EXTERNAL_STORAGE) to harvest contacts, SMS, images, and videos; the stolen data was uploaded to an exposed AWS S3 bucket used as the C2, and four unique samples with zero detection across major AV engines were identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
