Kimsuky APT Group Distributes Fake Security App Disguised as KISA Security Program

2021-06-03 Cybleinc

https://cyble.com/blog/kimsuky-apt-group-distributes-fake-security-app-disguised-as-kisa-security-program/

Thumbnail for Kimsuky APT Group Distributes Fake Security App Disguised as KISA Security Program

Cyble reported that Kimsuky, also known as Black Banshee, Thallium, and Velvet Chollima, distributed a fake Korean Internet and Security Agency mobile security app through malicious emails. The APK used package name com.kisa.mobile_security and was detected as an Android/Spy.Agent.BQS variant, with similarities to Cerberus-style Android spyware. Once installed and granted permissions, the app ran background services and receivers to read SMS, phone state, storage, and package-usage data, track location, overlay other apps, send SMS messages, upload or download files, and control processes. The campaign fits Kimsuky’s broader North Korea-linked spearphishing and social-engineering tradecraft against South Korea, Japan, and U.S.-linked targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe1a734019f0dc714bd3360e2369853… 2021-06-03 2021-09-12
URL http://app.at-me.ml/index.php?m… 2021-06-03 2021-09-12
URL http://app.at-me.ml/index.php?m… 2021-06-03 2021-09-12
DOMAIN app.at-me.ml 2021-06-03 2021-09-12
IPv4 104.128.239.70 2021-06-03 2021-09-12
URL http://app.at-me.ml/index.php 2021-06-03 2021-06-23
URL http://app.at-me.ml/index.php?m… 2021-06-03 2021-06-03
URL http://app.at-me.ml/ 2021-06-03 2021-06-03
DOMAIN amibreached.com 2021-06-03 2021-06-03

Related Actors

Related Reports

« Back