Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware

2022-10-25 S2W

https://medium.com/s2wblog/unveil-the-evolution-of-kimsuky-targeting-android-devices-with-newly-discovered-mobile-malware-280dae5a650f

Thumbnail for Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware

S2W Talon identified three Android malware families—FastFire, FastViewer, and FastSpy—while tracking Kimsuky mobile operations. The APKs disguise themselves as Google Security Plugin or Hancom Office Viewer; FastFire uses Firebase Cloud Messaging for command delivery, while FastViewer steals device data and downloads FastSpy, an AndroSpy-based remote access tool that communicates over TCP/IP. The report links the activity to Kimsuky through prior AppleSeed mobile activity, infrastructure overlaps, and mobile phishing against South Korean users, showing the group’s Android targeting has expanded beyond Windows-focused spear phishing.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN navernnail.com 2022-10-25 2026-01-14
DOMAIN goooglesecurity.com 2022-10-25 2023-11-01
IPv4 23.106.122.16 2022-10-25 2023-11-01
DOMAIN mc.pzs.kr 2022-05-18 2023-11-01
HASH 89f97e1d68e274b03bc40f6e06e2ba9a 2022-10-25 2023-04-19
HASH 3458daa0dffdc3fbb5c931f25d7a1ec0 2022-10-25 2023-04-19
HASH 884ff7e3a3cea5ce6371851f205d703… 2022-10-25 2022-10-25
HASH 539231dea156e29bd6f7ed8430bd08a… 2022-10-25 2022-10-25
HASH 8420236c32f0991feaa7869549abdb97 2022-10-25 2022-10-25
HASH 5d56371944dec9da57db95d0199dd920 2022-10-25 2022-10-25
HASH 59cb6bb54a6a222c863258baf9ee250… 2022-10-25 2022-10-25
HASH 031bde16d3b75083b0adda754aa982d… 2022-10-25 2022-10-25
HASH ae7436c00e2380cdabbdcccacf134b9… 2022-10-25 2022-10-25
HASH aefa23b91cc667be041cad40abbfa043 2022-10-25 2022-10-25
HASH 9722107fff4f3b2255556e0cf4d367c… 2022-10-25 2022-10-25
HASH c038b20f104be66550d8dd3366bf447… 2022-10-25 2022-10-25
HASH 38d1d8c3c4ec5ea17c3719af285247c… 2022-10-25 2022-10-25
HASH fdd0e18e841d3ec4e501dd8bf0da682… 2022-10-25 2022-10-25
HASH 1510780646e92cbefc5fb4f4d7d2997… 2022-10-25 2022-10-25
URL http://navernnail.com/fkwneovju… 2022-10-25 2022-10-25
URL http://mc.pzs.kr/themes/mobile/… 2022-10-25 2022-10-25
URL http://navernnail.com/fkwneovju… 2022-10-25 2022-10-25
URL http://goooglesecurity.com/fkwn… 2022-10-25 2022-10-25
URL http://navernnail.com/fkwneovju… 2022-10-25 2022-10-25
URL http://mc.pzs.kr/themes/mobile/… 2022-10-25 2022-10-25
URL http://mc.pzs.kr/themes/mobile/… 2022-10-25 2022-10-25

Related Actors

Related Reports

« Back