The Play Store has let another piece of malware through: this app pretended to be a file manager, but it was actually North Korean spyware.

Spyware disguised as a file manager. Cybercriminals have perfected their tactics to camouflage malware within apps that appear completely harmless. Many of them even function normally, but perform malicious actions in the background. File Manager, as its name suggests, presented itself as a file manager for Android, but in reality it hid something very different.
According to cybersecurity firm Lookout, File Manager concealed malware known as KoSpy, which they believe with “high confidence” was linked to North Korea. They reached this conclusion, among other things, by discovering that the malicious application uses domain names and IP addresses previously identified as being present in command and control infrastructure used by North Korean cybercriminal groups APT37 and APT43.
Leave a Comment