Kimsuky APT Group Distributes Fake Security App Disguised as KISA Security Program
2021-06-03 • Cybleinc •
Cyble reported that Kimsuky, also known as Black Banshee, Thallium, and Velvet Chollima, distributed a fake Korean Internet and Security Agency mobile security app through malicious emails. The APK used package name com.kisa.mobile_security and was detected as an Android/Spy.Agent.BQS variant, with similarities to Cerberus-style Android spyware. Once installed and granted permissions, the app ran background services and receivers to read SMS, phone state, storage, and package-usage data, track location, overlay other apps, send SMS messages, upload or download files, and control processes. The campaign fits Kimsuky’s broader North Korea-linked spearphishing and social-engineering tradecraft against South Korea, Japan, and U.S.-linked targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fe1a734019f0dc714bd3360e2369853… | 2021-06-03 | 2021-09-12 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-03 | 2021-09-12 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-03 | 2021-09-12 |
| DOMAIN | app.at-me.ml | 2021-06-03 | 2021-09-12 |
| IPv4 | 104.128.239.70 | 2021-06-03 | 2021-09-12 |
| URL | http://app.at-me.ml/index.php | 2021-06-03 | 2021-06-23 |
| URL | http://app.at-me.ml/index.php?m… | 2021-06-03 | 2021-06-03 |
| URL | http://app.at-me.ml/ | 2021-06-03 | 2021-06-03 |
| DOMAIN | amibreached.com | 2021-06-03 | 2021-06-03 |