KevDroid is an Android remote-access trojan used for mobile surveillance and information theft, publicly analyzed in 2018. It collects contacts, SMS messages, call logs, phone numbers, device identifiers, location information, installed-application inventories, emails, photos, and recorded telephone conversations. More advanced variants add camera and microphone recording, screenshot capture, browsing-history collection, file enumeration and retrieval, and collection of registered-account information. The malware retrieves commands from remote infrastructure and exfiltrates stolen data over HTTP. An advanced variant stages collected information locally and encrypts it with AES before transmission. One variant includes a native exploit for CVE-2015-3636 to obtain root access on vulnerable Android devices.
KevDroid has been distributed through spear-phishing attachments and trojanized Android applications impersonating antivirus software, a cryptocurrency widget, and a Winter Olympics application. Associated downloader applications were distributed outside Google Play and prompted users to update the application before retrieving the spyware and requesting its installation. The investigated campaign targeted Korean users. KevDroid has been associated with the North Korean espionage group APT37, also known as Reaper and Group 123, although Cisco Talos found insufficient evidence to establish confident attribution. The Windows malware PubNubRAT shared campaign infrastructure but is a separate family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One variant uses a known Android exploit (CVE-2015-3636) in order to get root access on the compromised Android device... It attempts to exploit the device using CVE-2015-3636 with the code available on GitHub. The purpose is to obtain the root permission on the compromised device. | We named this malware "KevDroid." ... Talos identified two variants of the Android Remote Administration Tool (RAT). Both samples have the same capabilities — namely to steal information on the compromised device (such as contacts, SMS and phone history) and record the victim's phone calls.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit 42 has looked further into EST’s findings and found a more advanced variant of the Trojan mentioned in their original article. Talos has written on this variant and named it KevDroid.
Unit 42 has looked further into EST’s findings and found a more advanced variant of the Trojan mentioned in their original article. Talos has written on this variant and named it KevDroid.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
When commanded to fetch a list of commands, the list is fetched from hxxp : //hakproperty.com/new/plat/pu[.]php?do=download_rc&aid=" + [64-bit android_id]
Once these downloaders are installed, they display a message prompting the user to update the application. If the user follows the prompts, the downloader retrieves the payload and saves it to the external device memory as AppName.apk . The payload is then loaded prompting the user again to confirm its installation before it is finally installed on the device.
The purpose of the application is to steal information stored on the device. Here is the list of stolen information: Installed applications, Phone number, Phone Unique ID, Location, Stored contacts information, Stored SMS, Call logs, Stored emails, Photos, Recording calls.
This sample has the following abilities: Capture screenshots (saved as 96_d[TS].jpg )
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android malware family in the Reaper/APT37 mobile arsenal.
Listed as malware used by Group123; its capabilities are not described.
Android spyware linked to the North Korean Reaper/APT37 group. It is delivered via trojanized Android apps and downloaders, can record audio and video, capture screenshots, collect device information, fetch files and commands, root the device using a bundled binary, and exfiltrate call recordings, call logs, SMS history, contacts, and account information to attacker-controlled infrastructure.
Android RAT with two variants that steals device information including contacts, SMS, call logs, emails, photos, location, installed apps, and recordings of phone calls. The second variant adds camera recording, audio recording, web history theft, file theft, and attempts to gain root privileges on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.