s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.kospy

📛 Threat Title

Malware family: KoSpy

Category: KoSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.kospy`. Printable name: KoSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.kospy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.kospy

IOC database

Type
domain
Value
apk.kospy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.kospy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.kospy

References (1)

Remediations (10)

  • web:cybernoz.com

    The North Korea-linked threat actor known as ScarCruft is said to have been behind a never-before-seen Android surveillance tool named KoSpy targeting Korean and English-speaking users. Lookout, which shared details of the malware campaign, said the earliest versions date back to March 2022. The most recent samples were flagged in March 2024. It's not clear how successful these efforts were ...

  • web:cybersecurefox.com

    Cybersecurity researchers at Lookout have uncovered a sophisticated Android spyware campaign dubbed " KoSpy ," attributed to the North Korean state-sponsored threat actor APT37 (ScarCruft). The malware was distributed through legitimate channels, including Google Play Store and APKPure, marking a significant escalation in mobile threat sophistication. Campaign Overview and Target Scope The ...

  • web:malpedia.caad.fkie.fraunhofer.de

    KoSpy can collect extensive data, such as SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The spyware has Korean language support with samples distributed across Google Play and third-party app stores such as Apkpure.

  • web:thehackernews.com

    KoSpy is the second North Korea-aligned Android malware family to be documented this week after DocSwap, which cybersecurity company S2W described as masquerading as a document viewing authorization app ("문서열람 인증 앱," package name - "com.security.library") and using a fake page impersonating CoinSwap on the C2 IP address used for ...

  • web:www.indrastra.com

    KoSpy is not an isolated case. Just this week, cybersecurity firm S2W documented another North Korea-aligned Android malware , DocSwap, masquerading as a document-viewing authorization app aimed at South Korean users.

  • web:www.linkedin.com

    Research suggests North Korea's ScarCruft group, active since 2012, is deploying KoSpy malware to spy on Android users, targeting Korean and English speakers.

  • web:www.lookout.com

    Lookout Threat Lab researchers have discovered a novel Android surveillance tool, dubbed KoSpy , which appears to target Korean and English-speaking users. The spyware, attributed with medium confidence to the North Korean APT group ScarCruft (also known as APT37), is a relatively new family with early samples going back to March 2022.

  • web:www.pcrisk.com

    Moreover, malware can spread to other devices, infecting them, or deploying additional harmful payloads. What is the purpose of KoSpy ? KoSpy is spyware designed to steal sensitive information from Android devices. It collects data such as SMS messages, call logs, location, files, and even records audio, takes photos, or tracks keystrokes.

  • web:www.security.land

    The North Korean state-sponsored hacking group ScarCruft (also known as APT37) has been identified deploying a new Android spyware dubbed 'KoSpy' to conduct cyber espionage activities targeting Korean and English language users. The malware's activity was first detected in March 2022, with the latest samples discovered in March 2024.

  • web:www.toddpigram.com

    The North Korea-linked threat actor known as ScarCruft is said to have been behind a never-before-seen Android surveillance tool named KoSpy targeting Korean and English-speaking users.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.