SK TelecomFraud

Malware family · 4 sample(s) · 4 indicator record(s) · 2 signing certificate(s)

About SK TelecomFraud

SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.

Indicators

IndicatorTypeSampleFirst seen
115.23.172.67/sms_admin/ ip 0eef59d4a6e6… 2015-10-28
115.23.172.67/sms_admin/ ip 20c159ee7b90… 2015-12-21
115.23.172.67/sms_admin/ ip 6d7cc07bae72… 2015-05-05
58.64.187.126:8087/sms_admin/ ip 29f84d309560… 2016-01-03