North Korean hackers use Google Play to distribute spyware

*Click the Title above to view complete article on https://www.24newshd.tv/.

2025-03-13T22:03:05+05:00 News Desk

A North Korean APT group has been targeting Korean and English-speaking users with an Android surveillance tool distributed via Google Play, according to cybersecurity firm Lookout.

Named KoSpy, the spyware has been active since March 2022, disguised as utility apps to trick unsuspecting users. It leverages Google Play and Firebase Firestore for app distribution and to fetch configuration data.

KoSpy has been linked to North Korea's APT group ScarCruft, also known as APT37, which has been operating since 2012. This group primarily targets entities in South Korea, but its reach extends to countries such as China, India, Japan, Kuwait, Nepal, Romania, Russia, Vietnam, and various Middle Eastern nations.

KoSpy has been observed masquerading as five types of applications: a phone manager, file manager, smart manager, software update utility, and a fake security app.

Once installed, the spyware retrieves configuration data from Firebase Firestore, enabling the attackers to remotely control the spyware, toggle its functionality, and change its command-and-control (C&C) server as needed.

The malware then checks if the device is an emulator and verifies if the current date surpasses a hardcoded activation date.

KoSpy is capable of collecting a wide range of data, including SMS messages, call logs, device location, screenshots, audio recordings via the phone’s microphone, photos, file and folder access, keystrokes, Wi-Fi network details, and a list of installed apps.

The stolen data is encrypted before being transmitted to a remote server. Lookout identified five Firebase projects and C&C servers used by the malware.

"Lookout researchers believe that the KoSpy campaign primarily targeted Korean and English-speaking users. More than half of the affected apps feature Korean language titles, and the user interface supports both English and Korean," the cybersecurity firm stated.

Some of the KoSpy apps were found on Google Play and the third-party app store Apkpure. All these apps have now been removed from Google Play.

Lookout attributes KoSpy to the North Korean APT group ScarCruft with moderate confidence, but also notes that APT43, another North Korean hacking group known as Kimsuky or Thallium, may have used the spyware as well.

View More News