#KoSpy

Malware/Tool

2024-12-11 • Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea

KoSpy is Android surveillance malware attributed with medium confidence to North Korean group ScarCruft, also known as APT37. Active since at least March 2022, it masqueraded as Korean- and English-language utility applications distributed through Google Play and third-party stores. KoSpy retrieves an encrypted on/off flag and command-and-control address from Firebase Firestore, checks for emulators and a hardcoded activation date, and dynamically downloads surveillance plugins. Those plugins collect SMS messages, call logs, location, files, audio recordings, and screenshots. Collected data is encrypted with a hardcoded AES key before exfiltration, while the two-stage configuration lets operators disable the spyware or rotate infrastructure.

Tagged Reports

« Back