216.73.216.6

North Korean APT37 Mobile Spyware Discovered

· Published 12/04/2025 17:53 · Modified 14/04/2025 12:17

Export JSON

Essential information

Published
12/04/2025 17:53
Modified
14/04/2025 12:17
Tags
2025-04-12 android apt apt37 konni kospy north korea scarcruft spyware surveillance
Related entities
1 intrusion sets (apt), 2 malware

Description

A new called has been attributed to the North Korean group (). The malware, active since March 2022, targets Korean and English-speaking users by masquerading as utility apps. uses a two-stage C2 infrastructure, retrieving initial configurations from Firebase cloud databases. It can collect extensive data, including SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The has been distributed through Google Play and third-party app stores. Evidence suggests infrastructure sharing with APT43 (Kimsuky), another North Korean state-sponsored group. 's capabilities include collecting sensitive information, recording audio, capturing screenshots, and keylogging. The campaign targets Korean and English speakers, with samples available on Google Play and third-party stores.

External references