Korean Smishing SMS Stealer (provisional)

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s) · Active 2018-12-07 → 2019-01-08 (experimental)

About Korean Smishing SMS Stealer (provisional)

Korean Smishing SMS Stealer (provisional) is a Korean SMS-stealing/smishing Android RAT disguised as a mobile wedding invitation lure (package com.android.systemsetting). It intercepts and exfiltrates SMS and MMS and device data, registers a DeviceAdmin receiver, and can place calls and install or delete packages, using SMS/MMS receivers and background services to drive collection. Stolen data is posted to an http /sms endpoint (observed C2 23.238.171.77). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
23.238.171.77/sms ip 32dc8100654e… 2018-12-07
23.238.171.77/sms ip 4b1cd7a6718e… 2019-01-08