“The malicious app performs an XOR (0xCC) operation on the ‘security.db’ file in a subdirectory, which drops an APK file and loads the DEX file stored within it,” explained the report detailing the threat. A sophisticated malware campaign targeting mobile users in South Korea has been uncovered, with clear links to North Korean threat actors. While the researchers at S2W Threat Research and Intelligence Center detected that the malware, which they have named “DocSwap” after discovering a phishing page impersonating CoinSwap at the command and control infrastructure. The researchers noted that the malicious app was first signed on December 13, 2024, and represents a previously unidentified type of threat specifically designed to target South Korean users. Security researchers recommend extreme caution when installing mobile applications, particularly those requesting accessibility permissions or claiming to be document authentication tools from uncertain sources. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. S2W has attributed this campaign to a North Korean threat actor they track as puNK-004, noting similarities to infrastructure previously used by the Kimsuky group. Upon execution, DocSwap aggressively requests numerous permissions including access to call logs, contacts, SMS messages, external storage, and phone capabilities. The sophisticated malware employs a multi-stage infection process that begins with decrypting an obfuscated file within the package. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. The malicious application, masquerading as a “Document Viewing Authentication App” (문서열람 인증 앱). DocSwap communicates with a hardcoded command and control server at 204.12.253[.]10:6834, receiving instructions through a sophisticated command structure.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 13 Mar 2025 11:20:08 +0000