Kimsuky Distributing Malicious Mobile App via QR Code
2025-12-16 • ENKI •
https://www.enki.co.kr/en/media-center/blog/kimsuky-distributing-malicious-mobile-app-via-qr-code
ENKI analyzed recent DOCSWAP Android variants that used phishing websites, QR-code redirection, notification prompts, and delivery-themed decoys to lure mobile users into installing malicious APKs. The report attributes the activity to Kimsuky based on shared C&C infrastructure, Korean-language comments, overlap with Million OK-style phishing infrastructure, and related Naver and Kakao credential-harvesting sites. The SecDelivery.apk sample decrypts an embedded security.dat APK through a native library, registers com.delivery.security.MainService, and maintains execution with Android broadcast receivers for reboot and power events. Its RAT service connects to 27.102.137[.]181:50005, supports 57 commands, and records Accessibility Service events for keylogging, showing how the campaign combines mobile phishing, credential theft, and remote-control capabilities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 27ea7ef88724c51bbe3ad42853bbc204 | 2025-12-16 | 2026-01-20 |
| HASH | 858588b7c5331c948fb3e84d9b4ddbb7 | 2025-12-16 | 2026-01-20 |
| HASH | c90ee7d3b1226f73044e7ae635493d31 | 2025-12-16 | 2026-01-20 |
| HASH | 86da5e00a9c73c9cb0855805cbc38c4a | 2025-12-16 | 2026-01-20 |
| HASH | 436287ad0ea3a9e94cd4574d54d0dec5 | 2025-12-16 | 2026-01-20 |
| HASH | 36677d732da69b7a81a46f9a06c36260 | 2025-12-16 | 2026-01-20 |
| HASH | 506e136336ca9d7246caf8c9011fe97e | 2025-12-16 | 2026-01-20 |
| HASH | 3a2a9f205c79ee45a84e3d862884fd72 | 2025-12-16 | 2026-01-20 |
| HASH | 2a7dab4c0f6507bc5fd826f9a336d50c | 2025-12-16 | 2026-01-20 |
| HASH | 2b99603cd8e69f82c064856d6ff63996 | 2025-12-16 | 2026-01-20 |
| HASH | 03a117c6cb86859623720e75f839260a | 2025-12-16 | 2026-01-20 |
| URL | https://delivery.cjlogistics.kr… | 2025-12-16 | 2026-01-20 |
| DOMAIN | delivery.cjlogistics.kro.kr | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.181 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.138.163 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.138.181 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.106 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.93 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.180 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.214 | 2025-12-16 | 2026-01-20 |