Ricochet Chollima Using KoSpy Android Spyware

2025-03-17 Poly Swarm

https://blog.polyswarm.io/ricochet-chollima-using-kospy-android-spyware

Thumbnail for Ricochet Chollima Using KoSpy Android Spyware

KoSpy is Android spyware linked to Ricochet Chollima, also known as APT37, Inky Squid, RedEyes, ScarCruft, and Reaper. The malware masquerades as utility apps, has appeared in Google Play and third-party stores such as Apkpure, and retrieves an encrypted Firebase Firestore configuration containing an operator-controlled enable switch and C2 address. After emulator and activation-date checks, KoSpy loads plugins from C2 to collect SMS messages, call logs, location data, files, audio recordings, and screenshots, then encrypts stolen data before exfiltration. Infrastructure such as st0746.net resolving to 27.255.79.225 overlaps with domains tied to Konni RAT and Velvet Chollima activity, suggesting shared or related North Korean resources.

Indicators of Compromise

Type Value First Seen Last Seen
HASH da56b0416b205b36337af2273896744… 2025-03-17 2025-03-17
DOMAIN nidlogon.com 2025-03-12 2025-03-17
DOMAIN st0746.net 2025-03-12 2025-03-17
DOMAIN naverfiles.com 2025-03-12 2025-03-17
IPv4 27.255.79.225 2025-03-12 2025-03-17

Related Actors

Related Reports

« Back