logo

Android Spyware Targeting Users In South Korea

ID: 3c6d0910-805a-5554-938b-8a81df073fbb

STIX ID: report--3c6d0910-805a-5554-938b-8a81df073fbb

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-02-17

Date Updated: 2026-07-16

...
...

**Executive Summary:** A previously undetected Android spyware campaign active since June 2024 targets individuals in South Korea by distributing malicious APKs that request minimal permissions (READ_SMS, READ_CONTACTS, READ_EXTERNAL_STORAGE) to harvest contacts, SMS, images, and videos; the stolen data was uploaded to an exposed AWS S3 bucket used as the C2, and four unique samples with zero detection across major AV engines were identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.