Lookout Discovers North Korean APT37 Mobile Spyware
2025-03-12 • Lookout •
Lookout identifies KoSpy as an Android spyware family attributed with medium confidence to North Korea-linked APT37, also known as ScarCruft, targeting Korean and English-speaking users. Samples masquerade as utility apps such as file managers, software update tools, and Kakao-themed security apps, with distribution observed through Google Play and third-party stores. KoSpy retrieves an initial encrypted configuration from Firebase Firestore, uses a two-stage C2 model to obtain plugin and surveillance settings, and can collect SMS messages, call logs, location, files, audio, screenshots, keystrokes, Wi-Fi details, and installed-app lists. Lookout notes infrastructure overlap with APT43/Kimsuky-related activity, including the KoSpy C2 domain st0746[.]net resolving to an IP previously associated with Korea-focused malicious domains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | nidlogon.com | 2025-03-12 | 2025-03-17 |
| DOMAIN | st0746.net | 2025-03-12 | 2025-03-17 |
| DOMAIN | naverfiles.com | 2025-03-12 | 2025-03-17 |
| IPv4 | 27.255.79.225 | 2025-03-12 | 2025-03-17 |
| HASH | f08f036a0c79a53f6b0c9ad84fb6eac… | 2025-03-12 | 2025-03-12 |
| HASH | b84604cad2f3a80fb50415aa069cce7… | 2025-03-12 | 2025-03-12 |
| HASH | 062a869caac496d0182decfadc57a23… | 2025-03-12 | 2025-03-12 |
| HASH | 3278324744e14ddf4f4312d375f82b3… | 2025-03-12 | 2025-03-12 |
| HASH | 2d1537e92878a3a14b5b3f55b32c91b… | 2025-03-12 | 2025-03-12 |
| HASH | df39ab90c89aa77a92295721688b18e… | 2025-03-12 | 2025-03-12 |
| HASH | 985fd1f74eb617b1fea17095f9e991d… | 2025-03-12 | 2025-03-12 |
| HASH | 1a167b65be75fd0651bbda072c85662… | 2025-03-12 | 2025-03-12 |
| HASH | ea6d12e4a465a7a44cbad12659ade8a… | 2025-03-12 | 2025-03-12 |
| HASH | 1cc97e490b5f8a582b6b03bdba58cb5… | 2025-03-12 | 2025-03-12 |
| HASH | 911d9f05e1c57a745cb0c669f3e1b67… | 2025-03-12 | 2025-03-12 |
| HASH | cd62a9ab320b4f6be49be11c9b1d2d5… | 2025-03-12 | 2025-03-12 |
| HASH | 5639fa1fa389ed32f8a8d1ebada8bbb… | 2025-03-12 | 2025-03-12 |
| HASH | 744e5181e76c68b8b23a19b939942de… | 2025-03-12 | 2025-03-12 |
| [email protected] | 2025-03-12 | 2025-03-12 | |
| DOMAIN | crowdon.info | 2025-03-12 | 2025-03-12 |
| DOMAIN | resolveissue.org | 2025-03-12 | 2025-03-12 |
| DOMAIN | noticeofpleadings.com | 2020-11-22 | 2025-03-12 |