Kimsuky APT Deploys Fake App As KISA Security Program
ID: b699b470-2bf7-5cd2-93ca-9f0f2cd22209
STIX ID: report--b699b470-2bf7-5cd2-93ca-9f0f2cd22209
Feed Name: Cyble Blog
Threat Score
**Executive summary:** Cyble reports that the North Korean-linked APT Kimsuky distributed a trojanized Android app impersonating the Korean Internet and Security Agency (KISA); when installed the app (SHA256 fe1a7340...) requests extensive permissions and performs SMS capture, location tracking, overlays, file access/deletion, and exfiltration to a C2 (http://app.at-me.ml/), with observed IoCs and MITRE ATT&CK mappings and recommended mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
