KevDroid is an Android remote access trojan and spyware family associated with the North Korean threat actor APT37, also known as ScarCruft, Reaper, Group 123, and Red Eyes. It has been observed in mobile espionage operations using trojanized Android applications and socially themed lures rather than broad app-store distribution. Reported lure themes included fake security software and trojanized applications themed around cryptocurrency and the PyeongChang Winter Games.
KevDroid is designed to collect extensive information from compromised Android devices. Documented capabilities include theft of contacts, SMS messages, call logs, phone history, installed application lists, device identifiers, phone numbers, account information, web history, photos, and selected files. More advanced variants can capture screenshots, list files on the device, retrieve specific files, record audio and video, and record incoming and outgoing phone calls. Stolen data is staged locally and encrypted before exfiltration to attacker-controlled infrastructure.
Multiple variants have been reported. Earlier samples relied in part on an open-source call-recording component, while later variants implemented their own call-recording functionality and expanded surveillance features. At least one variant included an embedded exploit for CVE-2015-3636 to obtain root privileges on vulnerable Android devices, indicating an effort to deepen access and broaden collection. Researchers also identified downloader applications that retrieved and prompted installation of the spyware payload after presenting the user with an update prompt.
KevDroid is best characterized as Android surveillance malware used for targeted intelligence collection. Its observed tradecraft, victimology, and infrastructure overlap place it within the broader mobile toolkit used by APT37 against Korean and other strategically relevant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One variant uses a known Android exploit (CVE-2015-3636) in order to get root access on the compromised Android device... It attempts to exploit the device using CVE-2015-3636 with the code available on GitHub. The purpose is to obtain the root permission on the compromised device. | We named this malware "KevDroid." ... Talos identified two variants of the Android Remote Administration Tool (RAT). Both samples have the same capabilities — namely to steal information on the compromised device (such as contacts, SMS and phone history) and record the victim's phone calls.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Reaper Group’s Updated Mobile Arsenal KevDroid ... Fake AV Investigation Unearths KevDroid, New Android Malware
Unit 42 has looked further into EST’s findings and found a more advanced variant of the Trojan mentioned in their original article. Talos has written on this variant and named it KevDroid.
Unit 42 has looked further into EST’s findings and found a more advanced variant of the Trojan mentioned in their original article. Talos has written on this variant and named it KevDroid.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
When commanded to fetch a list of commands, the list is fetched from hxxp : //hakproperty.com/new/plat/pu[.]php?do=download_rc&aid=" + [64-bit android_id]
Once these downloaders are installed, they display a message prompting the user to update the application. If the user follows the prompts, the downloader retrieves the payload and saves it to the external device memory as AppName.apk . The payload is then loaded prompting the user again to confirm its installation before it is finally installed on the device.
The purpose of the application is to steal information stored on the device. Here is the list of stolen information: Installed applications, Phone number, Phone Unique ID, Location, Stored contacts information, Stored SMS, Call logs, Stored emails, Photos, Recording calls.
This sample has the following abilities: Capture screenshots (saved as 96_d[TS].jpg )
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android malware family in the Reaper/APT37 mobile arsenal.
Android spyware linked to the North Korean Reaper/APT37 group. It is delivered via trojanized Android apps and downloaders, can record audio and video, capture screenshots, collect device information, fetch files and commands, root the device using a bundled binary, and exfiltrate call recordings, call logs, SMS history, contacts, and account information to attacker-controlled infrastructure.
Android RAT with two variants that steals device information including contacts, SMS, call logs, emails, photos, location, installed apps, and recordings of phone calls. The second variant adds camera recording, audio recording, web history theft, file theft, and attempts to gain root privileges on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.