DocSwap is an Android surveillance malware family used in campaigns attributed or linked with varying confidence to North Korea-aligned activity, including reporting that associates it with Kimsuky and internal tracking of a related cluster as puNK-004. It masquerades as legitimate mobile applications, including document-viewing authentication or delivery-related apps, and has also been distributed through phishing infrastructure impersonating South Korean logistics services. Observed delivery methods include QR-code-driven phishing and smishing-style lures that redirect victims to mobile-focused pages and prompt installation of malicious APKs.
Technically, DocSwap uses staged loading and decryption to activate its payload. Observed variants decrypt embedded components, including an internal APK or dynamically loaded code, with newer samples adding native-library-based decryption compared with earlier Java-based routines. After installation, the malware requests broad Android permissions and establishes persistence by running a foreground service and registering broadcast receivers so its main service is relaunched on reboot and certain power events.
DocSwap functions as a full-featured Android remote access trojan and spyware platform. Reported capabilities include collection and transmission of SMS content and metadata, call logs, contacts, files, device and network information, and accessibility-derived keystroke or UI text capture. It also supports camera and microphone access, file upload and download, file and directory deletion, and remote command execution. Accessibility services are abused for keylogging and ongoing surveillance, and captured data may be stored locally before exfiltration. Multiple analyses describe a command set with extensive remote tasking for post-compromise control.
Targeting has been assessed as focused on Android users in South Korea, based on Korean-language lures, app naming, and logistics-themed impersonation. The malware reflects an espionage-oriented mobile collection capability with strong emphasis on stealth, persistence, and broad device surveillance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On January 21, 2025, a malicious app named “문서열람 인증 앱”(Document Viewing Authentication App) was identified. This app, a new type of malware not previously observed, impersonates a document-viewing authentication app. Additionally, a phishing page masquerading as Coin Swap was found at the C2 address, leading to the app being named DocSwap.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It decrypts the “security.db” file within the package using an XOR operation and dynamically loads a DEX file.
DocSwap has checked for the WRITE_EXTERNAL_STORAGE permission. Drinik can request the READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE Android permissions. TangleBot can request permission to view files and media. VajraSpy has also requested for android.permission.WRITE_EXTERNAL_STORAGE and android.permission.READ_EXTERNAL_STORAGE.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware family delivered via smishing/phishing-themed fake delivery apps. The analyzed sample decrypts an embedded APK, registers a persistent MainService, connects to a C2 server, and functions as both an infostealer and RAT. Capabilities include keylogging via Accessibility Service, audio/video capture, file operations, contact/SMS/call-log theft, location collection, and remote command execution.
An Android spyware attributed in the report to Kimsuky for espionage operations, delivered via QR phishing.
Android RAT delivered via QR-phishing; decrypts an embedded encrypted APK and launches a malicious service providing remote-access capabilities.
Android remote access trojan distributed via QR codes (quishing) that, once installed, provides access to messages, calls, files, camera, and microphone.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.