An Android spyware campaign targeted Korean-speaking users through phishing pages impersonating Woori Bank and promoting fraudulent loan offers. Victims were prompted to install a fake version of the bank’s WON app, which abused Android Accessibility Service to obtain broad permissions and harvest sensitive data, including contacts, SMS messages, call logs, audio, video, GPS location, installed app lists, screen text, and information entered into embedded fake web pages.
The malware used layered evasion and persistence techniques to hinder analysis and maintain access on infected devices. Researchers reported packed and obfuscated components, encrypted secondary DEX payloads, anti-sandbox checks, and encrypted command-and-control communications, with one server address retrieved through GitHub. The spyware also monitored device events such as BOOT_COMPLETED and outgoing calls, reflecting a financially themed mobile espionage operation that combined social engineering with native Android abuse and obfuscated code to sustain surveillance of South Korean victims.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Cyble analyzed a phishing campaign targeting Korean-speaking users that distributed an Android spyware app masquerading as Woori Bank’s WON app. The malware used packing, encrypted secondary DEX payloads, Accessibility abuse, and fake web pages to steal personal and device data from victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
blog.cyble.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.