pu NK-004
2025-03-13 • S2W • Detailed Analysis of DocSwap Malware Disguised as…
puNK-004 is S2W TALON's designation for a North Korea-linked, previously unidentified threat actor observed using the Android malware DocSwap. S2W assigned the name in March 2025 after analyzing an application disguised as a document-viewing authentication tool. The application was first identified in January 2025 and appeared designed for mobile users in South Korea. It requested extensive permissions, persisted through a foreground service and boot events, and abused accessibility services for keylogging. Through socket-based command and control, it could collect files and device information, record audio and video, manipulate the camera, and steal call logs, contacts, and messages. Infrastructure associated with the malware also hosted a phishing page impersonating a cryptocurrency service and later displayed characteristics that S2W considered a possible connection to another North Korean activity set, but the attribution remained tentative.
-
43
Related Actors
-
799
Related Reports