Kimsuky Distributing Malicious Mobile App via QR Code

2025-12-16 ENKI

https://www.enki.co.kr/en/media-center/blog/kimsuky-distributing-malicious-mobile-app-via-qr-code

Thumbnail for Kimsuky Distributing Malicious Mobile App via QR Code

ENKI analyzed recent DOCSWAP Android variants that used phishing websites, QR-code redirection, notification prompts, and delivery-themed decoys to lure mobile users into installing malicious APKs. The report attributes the activity to Kimsuky based on shared C&C infrastructure, Korean-language comments, overlap with Million OK-style phishing infrastructure, and related Naver and Kakao credential-harvesting sites. The SecDelivery.apk sample decrypts an embedded security.dat APK through a native library, registers com.delivery.security.MainService, and maintains execution with Android broadcast receivers for reboot and power events. Its RAT service connects to 27.102.137[.]181:50005, supports 57 commands, and records Accessibility Service events for keylogging, showing how the campaign combines mobile phishing, credential theft, and remote-control capabilities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 27ea7ef88724c51bbe3ad42853bbc204 2025-12-16 2026-01-20
HASH 858588b7c5331c948fb3e84d9b4ddbb7 2025-12-16 2026-01-20
HASH c90ee7d3b1226f73044e7ae635493d31 2025-12-16 2026-01-20
HASH 86da5e00a9c73c9cb0855805cbc38c4a 2025-12-16 2026-01-20
HASH 436287ad0ea3a9e94cd4574d54d0dec5 2025-12-16 2026-01-20
HASH 36677d732da69b7a81a46f9a06c36260 2025-12-16 2026-01-20
HASH 506e136336ca9d7246caf8c9011fe97e 2025-12-16 2026-01-20
HASH 3a2a9f205c79ee45a84e3d862884fd72 2025-12-16 2026-01-20
HASH 2a7dab4c0f6507bc5fd826f9a336d50c 2025-12-16 2026-01-20
HASH 2b99603cd8e69f82c064856d6ff63996 2025-12-16 2026-01-20
HASH 03a117c6cb86859623720e75f839260a 2025-12-16 2026-01-20
URL https://delivery.cjlogistics.kr… 2025-12-16 2026-01-20
DOMAIN delivery.cjlogistics.kro.kr 2025-12-16 2026-01-20
IPv4 27.102.137.181 2025-12-16 2026-01-20
IPv4 27.102.138.163 2025-12-16 2026-01-20
IPv4 27.102.138.181 2025-12-16 2026-01-20
IPv4 27.102.137.106 2025-12-16 2026-01-20
IPv4 27.102.137.93 2025-12-16 2026-01-20
IPv4 27.102.137.180 2025-12-16 2026-01-20
IPv4 27.102.137.214 2025-12-16 2026-01-20

Related Actors

Related Reports

« Back