Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware
2022-10-25 • S2W •
S2W Talon identified three Android malware families—FastFire, FastViewer, and FastSpy—while tracking Kimsuky mobile operations. The APKs disguise themselves as Google Security Plugin or Hancom Office Viewer; FastFire uses Firebase Cloud Messaging for command delivery, while FastViewer steals device data and downloads FastSpy, an AndroSpy-based remote access tool that communicates over TCP/IP. The report links the activity to Kimsuky through prior AppleSeed mobile activity, infrastructure overlaps, and mobile phishing against South Korean users, showing the group’s Android targeting has expanded beyond Windows-focused spear phishing.
Indicators of Compromise
Related Actors
Related Reports
2023-10-30 •
70% Match
#Kimsuky
#FastSpy
#FastViewer
#T1636.004
#T1420
#T1533
#T1437.001
#T1646
#T1624.001
Shares tags: Kimsuky, FastSpy, FastViewer • Same author: S2W
Shares tag: Kimsuky • Published within a month
Shares tag: Kimsuky • Published within a month
Shares tag: Kimsuky • Published within a month
Shares tag: Kimsuky • Published within a week
Shares tag: Kimsuky • Same author: S2W