KoSpy is an Android spyware family associated with a North Korean espionage campaign and attributed with high confidence to the North Korean government. It has been linked in reporting to infrastructure overlaps with APT37, also known as ScarCruft, and APT43, though the campaign is characterized primarily as targeted surveillance rather than financially motivated activity.
KoSpy has been observed masquerading as benign Android applications, including utility-themed apps such as a file manager, and was distributed through both official and third-party Android app stores, including Google Play and APKPure. Available reporting indicates a low-volume, highly selective operation likely aimed at specific individuals rather than broad consumer infection. Targeting assessments point to Android users in South Korea, particularly Korean- or English-speaking victims.
The malware’s functionality is consistent with full-device surveillance. Reported capabilities include collection of SMS messages, call logs, location data, stored files, keystrokes, Wi-Fi information, and installed application lists. It can also record audio, capture screenshots, and take photographs using the device camera. KoSpy has been reported to retrieve initial configuration data from cloud-backed infrastructure, supporting flexible tasking and operational control.
The campaign reflects DPRK mobile espionage tradecraft focused on covert intelligence collection from Android devices. Public reporting indicates that identified malicious applications were removed from app stores and associated cloud projects were disabled, while known samples are blocked by Google Play Protect on supported Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lookout Discovers New Spyware by North Korean APT37 KoSpy
Lookout details an espionage campaign involving several different samples of an Android spyware it calls KoSpy, which the company attributes with “high confidence” to the North Korean government.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
According to Lookout, KoSpy collects “an extensive amount of sensitive information,” including: SMS text messages, call logs, the device’s location data, files and folders on the device... and a list of installed apps.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spyware family attributed in the content to North Korean APT37.
KoSpy is Android malware associated with ScarCruft that previously infiltrated Google Play.
A surveillance malware/tool referenced as part of Kimsuky Android espionage operations and explicitly contrasted with the Android TV botnets under discussion.
Android surveillance tool used by ScarCruft; distributed via fake utility apps; earliest versions date to March 2022 with samples through March 2024.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.