FastSpy is an Android remote access tool associated with the North Korean espionage group Kimsuky. It is derived from the open-source AndroSpy codebase and has been used in mobile intrusion activity targeting South Korean victims. FastSpy has been observed as a second-stage payload in an infection chain involving the trojanized FastViewer application, which impersonates a legitimate Android document viewer. In that chain, FastViewer activates malicious behavior when a victim opens an attacker-crafted document, collects device information, and then downloads and executes FastSpy in memory.
FastSpy functions as a remote access capability for Android devices and communicates with attacker-controlled infrastructure over TCP/IP to receive commands. Its role in Kimsuky operations reflects the group’s expansion of long-running espionage tradecraft from desktop-focused spearphishing into Android mobile surveillance and post-compromise access. Reported activity places FastSpy within a broader cluster of Kimsuky mobile malware that also includes FastFire and FastViewer, indicating sustained investment in Android tooling for intelligence collection against targets of interest to the DPRK, particularly in South Korea.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FastSpy is a remote access tool based on AndroSpy. ... The FastViewer malware downloads FastSpy, and receives commands from the attacker’s server through TCP/IP protocol.
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky
7 distinct techniques documented for this family, organized by ATT&CK tactic.
For instance, Kimsuky was recently observed using an IP validation method as part of its GoldDragon infection mechanism. The same Intrusion Set also newly implemented a geofencing mechanism in their signature malware Konni RAT, and similar behaviour was observed in the FastSpy infection chain.
For instance, Kimsuky was recently observed using an IP validation method as part of its GoldDragon infection mechanism. The same Intrusion Set also newly implemented a geofencing mechanism in their signature malware Konni RAT, and similar behaviour was observed in the FastSpy infection chain.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access malware used as a secondary payload. It is based on AndroSpy and provides attacker command-and-control over infected devices via TCP/IP.
Android malware/infection chain associated with Kimsuky exhibiting geofencing-like behavior.
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.