No Result
View All Result
Friday, May 9, 2025
MM News
اردو
  • Home
  • Latest News
  • Showbiz
    (Credit: Instagram/kopykatsproduction)

    Anwar Maqsood’s stage play ‘House Arrest’ resumes in Islamabad after NOC reinstated

    Rabya Kulsoom

    Rabya Kulsoom joins list of Pakistani artists banned in India

    Alizeh Shah

    Alizeh Shah opens up about unethical practices in showbiz industry

    met gala 2025

    In pictures: Most stunning looks from the Met Gala 2025

    Margot Robbie

    Here’s why Margot Robbie stayed away from the Met Gala

    Kiara Advani

    Kiara Advani makes Met Gala debut, flaunts baby bump in Gaurav Gupta gown

  • Thought Box
  • Business
  • Opinions
  • Technology
  • The Other Side
MM News
  • Home
  • Latest News
  • Showbiz
    (Credit: Instagram/kopykatsproduction)

    Anwar Maqsood’s stage play ‘House Arrest’ resumes in Islamabad after NOC reinstated

    Rabya Kulsoom

    Rabya Kulsoom joins list of Pakistani artists banned in India

    Alizeh Shah

    Alizeh Shah opens up about unethical practices in showbiz industry

    met gala 2025

    In pictures: Most stunning looks from the Met Gala 2025

    Margot Robbie

    Here’s why Margot Robbie stayed away from the Met Gala

    Kiara Advani

    Kiara Advani makes Met Gala debut, flaunts baby bump in Gaurav Gupta gown

  • Thought Box
  • Business
  • Opinions
  • Technology
  • The Other Side
No Result
View All Result
No Result
View All Result
MM News
اردو
  • Latest
  • Showbiz
  • Thought Box
  • Business & Stock
  • Opinions
  • Technology
  • The Other Side-Pakistan
Home Technology

North Korean hackers use Google Play to distribute spyware

MM News Staff by MM News Staff
March 13, 2025
File photo

File photo

A North Korean advanced persistent threat (APT) group has been actively targeting Korean and English-speaking users with a sophisticated Android surveillance tool, according to cybersecurity firm Lookout.

The spyware, named KoSpy, has been in operation since March 2022, disguising itself as utility applications to deceive unsuspecting users. The malware was distributed via Google Play and leveraged Firebase Firestore to retrieve configuration data and manage its operations remotely.

Cybersecurity experts have attributed KoSpy to ScarCruft (APT37), a North Korean state-sponsored hacking group that has been active since 2012. While its primary focus remains South Korea, the group has expanded its operations to several countries, including China, India, Japan, Kuwait, Nepal, Romania, Russia, Vietnam, and various Middle Eastern nations.

KoSpy has been detected masquerading as various legitimate applications, such as phone managers, file managers, smart utilities, software update tools, and even fake security apps. Once installed, the spyware connects to Firebase Firestore to receive commands, allowing attackers to modify its behavior, control infected devices remotely, and alter its command-and-control (C&C) server as needed.

The malware employs several security evasion techniques, including emulator detection and an activation mechanism based on a hardcoded date.

Once active, KoSpy can collect a vast range of sensitive data, including SMS messages, call logs, device location, screenshots, microphone recordings, photos, keystrokes, and installed app lists. It also monitors Wi-Fi networks and encrypts the stolen data before transmitting it to remote servers.

Lookout researchers uncovered five Firebase projects and multiple C&C servers linked to the malware. The spyware primarily targeted Korean and English-speaking users, with most affected apps featuring Korean language titles and interfaces supporting both languages.

Some KoSpy-infected apps were found on Google Play and third-party app store Apkpure. However, all known malicious apps have now been removed from Google Play following security intervention.

ShareTweetSendShare
Previous Post

PSL-10 trophy unveiled

Next Post

Gold prices in Pakistan today- Friday 14 March, 2025

Related Stories

File photo
Technology

Pakistan govt issues advisory over suspected Indian cyber attack

May 6, 2025
image: PR
Technology

Brillanz Group secures license to launch TAM system in Pakistan

May 6, 2025
(Image: LinkedIn)
Technology

How to apply for ‘Google Career Certificates Scholarship Program 2025’

May 5, 2025
Snap chat file photo
Technology

Snapchat suffers global outage

May 4, 2025
Pic credit Hungama
Technology

India blocks Imran Khan, Bilawal Bhutto Zardari’s X accounts

May 4, 2025
Technology

Fee hike shakes Pakistani freelancers as Payoneer imposes new 3% withdrawal charges

May 3, 2025
(Representational Image)
Technology

PTA warns against using patched cell phones

May 5, 2025
NADRA logo
Technology

Now you can update birth, death and marital status through NADRA’s new app

May 1, 2025
(Starlink Logo)
Technology

PTA delays issuing license to Starlink

April 29, 2025
NADRA logo
Technology

Nadra introduces Pakistan’s first digital identity card

April 29, 2025
Next Post
file photo

Gold prices in Pakistan today- Friday 14 March, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending Stories

image: Online
Top News

Pakistan reopens airspace to all domestic and international airlines

by MM News Staff
May 9, 2025
file photo
Crime

NCIA points out social media accounts involved in anti-army propaganda

by MM News Staff
May 9, 2025
Representative image
Business & Stock

Forex rates in Pakistan today- May 9, 2025

by MM News Staff
May 9, 2025
representative image
Business & Stock

Gold prices in Pakistan today- May 9, 2025

by MM News Staff
May 9, 2025
Photo international media
Top News

Robert Francis Prevost becomes new pope

by MM News Staff
May 8, 2025

Opinion

Munir Ahmed OPED
Britain’s Interference in China and Domestic Challenges
April 29, 2025
- Munir Ahmed
nadeem moulvi
Revamping Pakistan's Outdated Education System
April 10, 2025
- MM News Staff
nadeem moulvi
PSL celebration or the bodies of children in Gaza?
April 9, 2025
- Nadeem Moulvi
No posts found
See all

Weather Updates

Thunderstorms and rain
Top News

Countrywide thunderstorms and rain expected until May 12

by MM News Staff
May 8, 2025

The Meteorological Department has forecast thunderstorms and rain across the country from today until...

Rains

Will Karachi receive rain tonight?

May 6, 2025
file Image by PMD

Weather updates for Karachi, other parts of the country

May 6, 2025
Rain and Thunderstorms

Rain and thunderstorms expected across Pakistan starting today

May 5, 2025
See all

Prices

representative image
Business & Stock

Gold prices in Pakistan today- May 9, 2025

by MM News Staff
May 9, 2025

Gold prices continued the downward trend in both the local and international markets yesterday,...

File photo

Will electricity become cheaper in FY2025–26?

May 8, 2025
(File)

Gold price drops Rs4200 per tola

May 8, 2025
Foreign Currency Rates

Foreign currency exchange rates in Pakistan, 8 May 2025

May 8, 2025
See all

Transport News

image: Online
Top News

Pakistan reopens airspace to all domestic and international airlines

by MM News Staff
May 9, 2025

The Pakistan Airports Authority (PAA) has officially announced that Pakistani airspace is now open...

(File Photo)

Karachi Airport to remain closed till midnight

May 8, 2025
(File Photo)

PIA issues passenger guidelines as Pakistan-India crisis deepens

May 8, 2025
Airspace

Airspace over Lahore, Islamabad, and Sialkot reopened: Airport Authority

May 8, 2025
See all

MM Digital (Pvt.) Ltd.

MM News is a subsidiary of the MM Group of Companies. It was established in 2019 with the aim of providing people of Pakistan access to unbiased information. Contact Details: 03200201537

Quick Links

  • Home
  • Advertise
  • MM News Urdu
  • The Other Side-Pakistan
  • Contact Us
  • Privacy Policy

Top Pages

  • Latest News
  • Showbiz
  • OP-ED
  • Technology
No Result
View All Result
  • Latest News
  • Showbiz
  • Thought Box
  • Business
  • Opinions
  • Technology

© Copyright 2024 MMNews - All Rights Reserved.