KoSpy is an Android spyware family associated with North Korean state-sponsored espionage and linked to APT37, also known as ScarCruft. It is designed for surveillance and information collection rather than financial theft. Malicious applications masquerading as legitimate utilities, including a file manager, have been distributed through Google Play and the third-party Android application marketplace APKPure. The applications include Korean- and English-language interfaces.
KoSpy collects SMS messages, call logs, device location, stored files and folders, user-entered keystrokes, Wi-Fi network information, and lists of installed applications. It can also record audio, take photographs using device cameras, and capture screenshots. It uses Google Cloud Firestore to retrieve initial configuration information. Its infrastructure has overlapped infrastructure previously associated with North Korean groups APT37 and APT43, although infrastructure overlap alone does not establish joint operation by those groups.
Google removed the identified malicious applications from Google Play and deactivated their associated Firebase projects. Google Play Protect blocks known versions on Android devices with Google Play Services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lookout details an espionage campaign involving several different samples of an Android spyware it calls KoSpy, which the company attributes with “high confidence” to the North Korean government.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
According to Lookout, KoSpy collects “an extensive amount of sensitive information,” including: SMS text messages, call logs, the device’s location data, files and folders on the device... and a list of installed apps.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spyware family attributed in the content to North Korean APT37.
KoSpy is Android malware associated with ScarCruft that previously infiltrated Google Play.
A surveillance malware/tool referenced as part of Kimsuky Android espionage operations and explicitly contrasted with the Android TV botnets under discussion.
Android surveillance tool used by ScarCruft; distributed via fake utility apps; earliest versions date to March 2022 with samples through March 2024.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.