FastFire is an Android malware family associated with the North Korean espionage group Kimsuky. It has been observed masquerading as a Google security plug-in and reflects Kimsuky’s expansion of mobile targeting against Android users, particularly in South Korea. At the time it was documented, FastFire appeared to still be under development, but its implemented functionality already showed a shift in Kimsuky tradecraft from earlier mobile malware that relied on conventional HTTP/S communications toward command delivery through Firebase Cloud Messaging.
After installation, FastFire hides its launcher icon to reduce user awareness and requests permissions consistent with intrusive device interaction, including overlay-related access. It generates a Firebase messaging token and reports that token to attacker-controlled infrastructure so the operators can push commands to the infected device. Embedded functionality included retrieval of phishing-themed HTML content and use of Android deep-linking to direct victims into specific application pages, indicating support for credential-harvesting or social-engineering workflows. The malware is therefore best understood as an Android trojanized espionage implant under active development rather than a mature commodity family.
FastFire is linked to Kimsuky, also tracked under aliases including Thallium and Black Banshee, a long-running North Korean threat actor known for spearphishing, account compromise, and intelligence collection against media, research, political, diplomatic, and other strategic targets. Reporting tied FastFire to the same broader Android malware cluster as FastViewer and FastSpy, which were used against South Korean victims, underscoring Kimsuky’s growing sophistication in mobile operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We named the three malicious APKs FastFire, FastViewer, and FastSpy... FastFire is a malicious APK currently being developed by the Kimsuky group, disguised as a Google security plug-in. It receives commands from Firebase...
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The group mainly attempts to collect by distributing malware and taking over accounts through spear-phishing attacks. | Kimsuky group conducts phishing attacks disguised as the site to hijack the accounts of large Korean portal sites such as Naver and Daum, FastFire malware also targets the two portal sites.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware disguised as a Google Security Plugin. It hides its launcher icon, sends a device token to attacker infrastructure, receives commands via Firebase Cloud Messaging, and can fetch attacker-controlled HTML/deep links targeting services such as Naver, Daum, and Facebook.
Android malware used by Kimsuky.
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.