Security News > 2025 > March > North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility Apps

2025-03-13 14:23
The North Korea-linked threat actor known as ScarCruft is said to have been behind a never-before-seen Android surveillance tool named KoSpy targeting Korean and English-speaking users. Lookout, which shared details of the malware campaign, said the earliest versions date back to March 2022. The most recent samples were flagged in March 2024. It's not clear how successful these efforts were. "
News URL
https://thehackernews.com/2025/03/north-koreas-scarcruft-deploys-kospy.html
Related news
- DoNot Team Linked to New Tanzeem Android Malware Targeting Intelligence Collection (source)
- Crypto-stealing iOS, Android malware found on App Store, Google Play (source)
- I'm a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice (source)
- North Korea targets crypto developers via NPM supply chain attack (source)
- SpyLend Android malware downloaded 100,000 times from Google Play (source)
- Bybit declares war on North Korea's Lazarus crime-ring to regain $1.5B stolen from wallet (source)
- FBI officially fingers North Korea for $1.5B Bybit crypto-burglary (source)
- Vo1d malware botnet grows to 1.6 million Android TVs worldwide (source)
- $1.5B Bybit Hack is Linked to North Korea, FBI Says, in Potentially the Largest Crypto Heist Ever (source)
- BadBox malware disrupted on 500K infected Android devices (source)