Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
Kimsuky, a North Korean threat actor, has been connected to a recent campaign that uses QR codes posted on phishing websites that imitate the Seoul-based transportation company CJ transportation (previously CJ Korea Express) to spread a new version of Android malware called DocSwap.
According to ENKI, the threat actor tricked victims into installing and running the malware on their mobile devices by using QR codes and notification pop-ups. The malicious program initiates a malicious service with RAT capabilities after decrypting an embedded encrypted APK.
The threat actor pretends the app is a secure, official release in order to fool victims into disregarding the warning and installing the virus because Android by default rejects apps from unknown sources and shows security warning...

