Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Kimsuky Hackers Use Weaponized QR Codes to Distribute Malicious Mobile Apps

Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky. This campaign uses weaponized QR codes and fraudulent delivery service impersonations to install remote access trojans on smartphones.

Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky. This campaign uses weaponized QR codes and fraudulent delivery service impersonations to install remote access trojans on smartphones.

The ENKI WhiteHat Threat Research Team identified the latest version of the "DOCSWAP" malware, distributed through phishing messages containing malicious URLs. These URLs direct users to QR codes that prompt them to switch to mobile devices. The QR codes lead to distribution servers hosting malicious Android applications disguised as legitimate services.

Researchers identified three additional malicious applications and seven command and control (C&C) servers using APK metadata and infrastructure overlaps.

The distribution process employs server-side logic to detect user device types, displaying security warnings and download prompts exclusively to Android users while blocking desktop browsers.

When users click the "Install security app" button, the server initiates an APK download and logs access attempts and transmission details. The malware infrastructure is located at IP address 27.102.137[.]181 and includes fake delivery tracking pages impersonating companies such as CJ Logistics.

The malicious application "SecDelivery.apk" utilizes a two-stage infection mechanism. Upon execution, it decrypts an embedded encrypted APK using a native decryption function. This approach uses multiple obfuscation layers, including bit inversion, 5-bit rotation, and XOR encryption, enhancing detection evasion capabilities.

Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky.
Noah Redmond · Thehackingpost

The decrypted payload launches a service providing remote access trojan functionality. The malware requests permissions such as file system access, SMS interception, and phone state monitoring. It also displays a fake authentication screen, maintaining deception while executing the payload.

The internal APK establishes command and control connections to the distribution server, executing 57 commands for data theft, audio recording, and device control.

Researchers identified multiple indicators linking this campaign to Kimsuky, including "Million OK!!!!" signature strings and infrastructure overlaps with known Kimsuky phishing campaigns. The delivery number "742938128549" is hardcoded within the APK.

Embedded Korean-language comments and distribution websites indicate the threat actors' Korean language proficiency and potential ties to North Korean operations.

Advertisement

The analysis revealed seven additional C&C servers and three malicious applications disguised as delivery services, cryptocurrency airdrops, and VPN applications. Proxy-based phishing sites were also documented, intercepting login credentials.

Security professionals recommend verifying link destinations before clicking and evaluating app permission requests conservatively. Organizations should implement mobile threat detection solutions, enforce application vetting policies, and educate employees about phishing techniques targeting mobile platforms.

This campaign highlights evolving North Korean capabilities in mobile exploitation, emphasizing the importance of mobile security awareness.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories