FastViewer Android Malware Linked with North Korean Threat Actor

BlackRock Android Malware

A team working with mobile security firm Talon Cyber Security identified a new trio of malicious packages targeting Android devices. All three malware packages are linked to a threat actor operating out of North Korea and known by the handle "Kimsuky group".

The three new malware variants are named FastFire, FastSpy and FastViewer. All three were found targeting devices that can run Android.

While FastFire is distributed in the guise of a Google security update for your device, FastViewer is posing as the Hancom Office Viewer application. The Hancom viewer is a legitimate application that has millions of downloads on the official Google Play Store. The malicious version that is really FastViewer has malicious code injected into the package.

On the surface, the malicious FastViewer behaves like a normal file viewer, but its malicious functionality kicks in when it opens a specially doctored file, created by the malware's authors. The malicious application does a byte check on the initial four bytes of the file being opened and if it meets the determined conditions, the malware contacts its command and control servers.

Once this happens, FastViewer also downloads the FastSpy malware on the infected device.

Kimsuky APT Group Releases Malware Threats Like FastViewer That Remote Control Other Devices

November 2, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.