#DocSwap
Malware/Tool
2025-03-13 • Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer
DocSwap is an Android remote-access Trojan distributed as a security-document viewer or other legitimate-looking mobile application. Recent versions decrypt an embedded secondary APK, register a malicious service, communicate with command-and-control infrastructure, and provide RAT capabilities. Kimsuky-linked operators used QR codes and notification pop-ups to persuade victims to install and run it. The latest samples preserve the behavior of earlier variants but use a different internal APK-decryption process, showing continued development of the family.
-
5
Tagged Reports
-
4
Unique Authors
-
314
Active Days