Kimsuky Hackers Use Weaponized QR Codes to Distribute Malicious Mobile Apps
Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky. This campaign uses weaponized QR codes and fraudulent delivery service impersonations to install remote access trojans on smartphones.
Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky. This campaign uses weaponized QR codes and fraudulent delivery service impersonations to install remote access trojans on smartphones.
The ENKI WhiteHat Threat Research Team identified the latest version of the "DOCSWAP" malware, distributed through phishing messages containing malicious URLs. These URLs direct users to QR codes that prompt them to switch to mobile devices. The QR codes lead to distribution servers hosting malicious Android applications disguised as legitimate services.
Researchers identified three additional malicious applications and seven command and control (C&C) servers using APK metadata and infrastructure overlaps.
The distribution process employs server-side logic to detect user device types, displaying security warnings and download prompts exclusively to Android users while blocking desktop browsers.
When users click the "Install security app" button, the server initiates an APK download and logs access attempts and transmission details. The malware infrastructure is located at IP address 27.102.137[.]181 and includes fake delivery tracking pages impersonating companies such as CJ Logistics.
The malicious application "SecDelivery.apk" utilizes a two-stage infection mechanism. Upon execution, it decrypts an embedded encrypted APK using a native decryption function. This approach uses multiple obfuscation layers, including bit inversion, 5-bit rotation, and XOR encryption, enhancing detection evasion capabilities.
Threat researchers have identified a mobile malware campaign attributed to the North Korea-linked threat actor Kimsuky.
The decrypted payload launches a service providing remote access trojan functionality. The malware requests permissions such as file system access, SMS interception, and phone state monitoring. It also displays a fake authentication screen, maintaining deception while executing the payload.
The internal APK establishes command and control connections to the distribution server, executing 57 commands for data theft, audio recording, and device control.
Researchers identified multiple indicators linking this campaign to Kimsuky, including "Million OK!!!!" signature strings and infrastructure overlaps with known Kimsuky phishing campaigns. The delivery number "742938128549" is hardcoded within the APK.
Embedded Korean-language comments and distribution websites indicate the threat actors' Korean language proficiency and potential ties to North Korean operations.
The analysis revealed seven additional C&C servers and three malicious applications disguised as delivery services, cryptocurrency airdrops, and VPN applications. Proxy-based phishing sites were also documented, intercepting login credentials.
Security professionals recommend verifying link destinations before clicking and evaluating app permission requests conservatively. Organizations should implement mobile threat detection solutions, enforce application vetting policies, and educate employees about phishing techniques targeting mobile platforms.
This campaign highlights evolving North Korean capabilities in mobile exploitation, emphasizing the importance of mobile security awareness.
Based on reporting by GBHackers.
