#KoSpy
Malware/Tool
KoSpy is Android surveillance malware attributed with medium confidence to North Korean group ScarCruft, also known as APT37. Active since at least March 2022, it masqueraded as Korean- and English-language utility applications distributed through Google Play and third-party stores. KoSpy retrieves an encrypted on/off flag and command-and-control address from Firebase Firestore, checks for emulators and a hardcoded activation date, and dynamically downloads surveillance plugins. Those plugins collect SMS messages, call logs, location, files, audio recordings, and screenshots. Collected data is encrypted with a hardcoded AES key before exfiltration, while the two-stage configuration lets operators disable the spyware or rotate infrastructure.
-
4
Tagged Reports
-
2
Unique Authors
-
97
Active Days