KoSpy

Malware family · 14 sample(s) · 14 indicator record(s) · 6 signing certificate(s) · Active 2025-02-07 (experimental)

About KoSpy

KoSpy is an Android surveillance tool attributed to the North Korean actor APT37 (ScarCruft / Reaper), disclosed by Lookout in 2025. Samples pose as utility apps (File Manager, Software Update, security helpers) and use a two-stage C2: the implant first pulls its live configuration and real C2 address from a Google Firebase project (hence the *.appspot.com indicators such as project-27ef0, smart-743cf and version-25b53), then beacons to the operator server. It collects SMS, call logs, location, audio recordings, screenshots, keystrokes and installed-app lists, fetching payloads on demand. Targets Korean- and English-speaking victims. APT / state-aligned.

Indicators

IndicatorTypeSampleFirst seen
mydb-a1554.appspot.com domain 0374615eeca4… 2025-02-07
mydb-a1554.appspot.com domain f1b33341b0dc… 2025-02-07
mydb-a1554.appspot.com domain f3e004f888be… 2025-02-07
project-27ef0.appspot.com domain 90ec29bafccc… 2025-02-07
project-27ef0.appspot.com domain fe1fb1eaf852… 2025-02-07
project-75f80.appspot.com domain 3ca78cecb854… 2025-02-07
project-75f80.appspot.com domain aa2bbdde6566… 2025-02-07
project-75f80.appspot.com domain bf0150e1e31f… 2025-02-07
smart-743cf.appspot.com domain b0c0f38551a1… 2025-02-07
smart-743cf.appspot.com domain da56b0416b20… 2025-02-07
version-25b53.appspot.com domain 0329be10a5be… 2025-02-07
version-25b53.appspot.com domain 75d9353c8fd8… 2025-02-07
version-25b53.appspot.com domain cbcfcb8089ed… 2025-02-07
version-25b53.appspot.com domain d937ea795b97… 2025-02-07