## ScarCruft Launches KoSpy Android Malware
Security researchers at Lookout have uncovered a sophisticated Android surveillance tool named KoSpy, attributed to the North Korean threat actor ScarCruft. The malware campaign, targeting Korean and English-speaking users, has been active since March 2022, with the most recent samples detected in March 2024.
KoSpy masquerades as legitimate utility applications on Google Play Store, using names like “File Manager,” “Phone Manager,” and “Kakao Security.” These apps provide the promised functionality while secretly deploying spyware components in the background. Google has since removed these applications from the marketplace.
The malware employs a two-stage command-and-control approach, first contacting Firebase Firestore to retrieve the actual C2 server address. This technique provides flexibility and helps evade detection. KoSpy performs security checks to ensure it’s not running in an emulator and only activates after a hardcoded date.
Once active, KoSpy can collect extensive data including:
– SMS messages and call logs
– Device location
– Files in local storage
– Screenshots and keystrokes
– Wi-Fi network information
– Installed applications
– Audio recordings and photos
Researchers noted infrastructure overlaps between KoSpy and campaigns linked to another North Korean hacking group, Kimsuky (APT43).
## Contagious Interview Campaign Targets Developers
In a separate discovery, Socket identified six malicious npm packages deploying BeaverTail malware as part of North Korea’s “Contagious Interview” campaign. These typosquatting packages mimicked legitimate libraries and were downloaded over 330 times before removal.
The malware collects system information and steals credentials from web browsers and cryptocurrency wallets, including Solana and Exodus. The threat actors maintained GitHub repositories for five of these packages to appear legitimate.
## RustDoor and Koi Stealer Target Cryptocurrency Sector
Palo Alto Networks Unit 42 has identified another North Korean campaign using RustDoor (ThiefBucket) malware and a new macOS variant of Koi Stealer targeting the cryptocurrency sector.
The attack begins with a fake job interview project that, when executed via Microsoft Visual Studio, downloads RustDoor. This malware steals LastPass passwords from Chrome and establishes a reverse shell. The final stage deploys Koi Stealer, which impersonates Visual Studio to trick victims into entering system passwords, enabling further data theft.
These campaigns highlight the sophisticated social engineering tactics employed by North Korean state-sponsored actors to infiltrate networks and steal sensitive data and cryptocurrencies.
