Lookout Discovers North Korean APT37 Mobile Spyware

2025-03-12 Lookout

https://www.lookout.com/threat-intelligence/article/lookout-discovers-new-spyware-by-north-korean-apt37

Thumbnail for Lookout Discovers North Korean APT37 Mobile Spyware

Lookout identifies KoSpy as an Android spyware family attributed with medium confidence to North Korea-linked APT37, also known as ScarCruft, targeting Korean and English-speaking users. Samples masquerade as utility apps such as file managers, software update tools, and Kakao-themed security apps, with distribution observed through Google Play and third-party stores. KoSpy retrieves an initial encrypted configuration from Firebase Firestore, uses a two-stage C2 model to obtain plugin and surveillance settings, and can collect SMS messages, call logs, location, files, audio, screenshots, keystrokes, Wi-Fi details, and installed-app lists. Lookout notes infrastructure overlap with APT43/Kimsuky-related activity, including the KoSpy C2 domain st0746[.]net resolving to an IP previously associated with Korea-focused malicious domains.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN nidlogon.com 2025-03-12 2025-03-17
DOMAIN st0746.net 2025-03-12 2025-03-17
DOMAIN naverfiles.com 2025-03-12 2025-03-17
IPv4 27.255.79.225 2025-03-12 2025-03-17
HASH f08f036a0c79a53f6b0c9ad84fb6eac… 2025-03-12 2025-03-12
HASH b84604cad2f3a80fb50415aa069cce7… 2025-03-12 2025-03-12
HASH 062a869caac496d0182decfadc57a23… 2025-03-12 2025-03-12
HASH 3278324744e14ddf4f4312d375f82b3… 2025-03-12 2025-03-12
HASH 2d1537e92878a3a14b5b3f55b32c91b… 2025-03-12 2025-03-12
HASH df39ab90c89aa77a92295721688b18e… 2025-03-12 2025-03-12
HASH 985fd1f74eb617b1fea17095f9e991d… 2025-03-12 2025-03-12
HASH 1a167b65be75fd0651bbda072c85662… 2025-03-12 2025-03-12
HASH ea6d12e4a465a7a44cbad12659ade8a… 2025-03-12 2025-03-12
HASH 1cc97e490b5f8a582b6b03bdba58cb5… 2025-03-12 2025-03-12
HASH 911d9f05e1c57a745cb0c669f3e1b67… 2025-03-12 2025-03-12
HASH cd62a9ab320b4f6be49be11c9b1d2d5… 2025-03-12 2025-03-12
HASH 5639fa1fa389ed32f8a8d1ebada8bbb… 2025-03-12 2025-03-12
HASH 744e5181e76c68b8b23a19b939942de… 2025-03-12 2025-03-12
EMAIL [email protected] 2025-03-12 2025-03-12
DOMAIN crowdon.info 2025-03-12 2025-03-12
DOMAIN resolveissue.org 2025-03-12 2025-03-12
DOMAIN noticeofpleadings.com 2020-11-22 2025-03-12

Related Actors

Related Reports

« Back