logo

Spyware Disguised As Korean App Targets Asia

ID: e08c4edd-eda7-56ae-903f-edd5756c5b6a

STIX ID: report--e08c4edd-eda7-56ae-903f-edd5756c5b6a

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-11-08

Date Updated: 2026-07-20

...
...

This Cyble report analyzes a mobile spyware variant masquerading as a Korean video app that targets users in China, Korea, and Japan to collect sensitive data (contacts, SMS, location, images) and exfiltrate it to attacker-controlled C2 servers for sextortion/blackmail. The analysis includes APK metadata (package org.nnnmbook.sytyd, SHA256 0bda73046fd733164877071d11318ec6dd56a6ea4e773c70ed5a3c8f7a244478), observed permissions and behaviors, screenshots of data collection/upload flows, MITRE ATT&CK mappings, and IoCs including multiple C2 URLs and an IP address, plus recommended defensive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.