Security researchers at Lookout have uncovered a sophisticated Android spyware operation linked to North Korean threat actors. Dubbed ‘KoSpy,’ the malware was distributed through at least five malicious applications on Google Play and the third-party store APKPure since March 2022.
## Malicious Apps and Distribution
The campaign, attributed to North Korean threat group APT37 (also known as ‘ScarCruft’), primarily targets Korean and English-speaking users. The malicious applications disguised themselves as:
– 휴대폰 관리자 (Phone Manager)
– File Manager (com.file.exploer)
– 스마트 관리자 (Smart Manager)
– 카카오 보안 (Kakao Security)
– Software Update Utility
Most of these apps provide some legitimate functionality while secretly loading the KoSpy spyware in the background. The exception is Kakao Security, which only displays a fake system window while requesting dangerous permissions.
## Technical Capabilities
Once installed, KoSpy employs several sophisticated techniques:
– Retrieves encrypted configuration from Firebase Firestore to evade detection
– Connects to command and control (C2) servers for instructions
– Performs anti-emulation checks to avoid analysis
– Can be remotely activated or deactivated
The spyware’s extensive surveillance capabilities include:
– Intercepting SMS messages and call logs
– Real-time GPS location tracking
– Accessing and exfiltrating files from storage
– Recording audio via the device’s microphone
– Capturing photos and videos
– Taking screenshots
– Recording keystrokes through Accessibility Services
## Attribution and Mitigation
Researchers linked the campaign to North Korea based on IP addresses previously associated with North Korean operations, domains used for Konni malware distribution, and infrastructure overlapping with APT43, another DPRK-sponsored threat group.
Google has confirmed to BleepingComputer that all identified KoSpy apps have been removed from Google Play, and the corresponding Firebase projects have been taken down. Google Play Protect can block known versions of this malware.
Users who may have installed these applications should manually uninstall them and scan their devices with security tools. In severe cases, a factory reset is recommended.
