북한 해킹 조직 김수키 에서 만든 악성코드-KISA Mobile Security(2021.07.1)
2021-09-12 • Sakai • Malware created by North Korean hacking organization Kim Suki - KISA Mobile Security (2021.07.1) •
The source analyzes KISA Mobile Security.apk, a fake Android security app attributed to the Kimsuky/Thallium North Korean hacking group and distributed through email while impersonating Korea Internet and Security Agency software. Once installed, the malware runs in the background and requests broad permissions including internet access, external storage, phone state, SMS read/receive/send and boot persistence. The code excerpts show collection of device/location and SMS data, overlay-style behavior, temporary file creation and exfiltration routines. The report provides representative hashes for the APK and identifies the package as com.kisa.mobile_security, making it useful for tracking Kimsuky mobile malware masquerading as trusted Korean security tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c31b38e79c5ee96161527fd72e2672e… | 2021-09-12 | 2021-09-12 |
| HASH | 4d3537c428f49696b78b115a8c2877b… | 2021-09-12 | 2021-09-12 |
| IPv4 | 49.1.1.11 | 2021-09-12 | 2021-09-12 |
| HASH | 16b3487022b674040227afc8979ffed… | 2021-06-23 | 2021-09-12 |
| HASH | e7caf25de7ce463a6f22ecb8689389ad | 2021-06-23 | 2021-09-12 |
| HASH | fe1a734019f0dc714bd3360e2369853… | 2021-06-03 | 2021-09-12 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-03 | 2021-09-12 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-03 | 2021-09-12 |
| DOMAIN | app.at-me.ml | 2021-06-03 | 2021-09-12 |
| IPv4 | 104.128.239.70 | 2021-06-03 | 2021-09-12 |