At least 5 North Korean spy apps have been found on Google Play — what you need to know

Google Play logo on an android smartphone with corner hole punch camera
(Image credit: Shutterstock)

You always need to be careful about the apps you install on Android, even if you download them directly from Google Play. Researchers have found at least 5 different apps, which have passed Google Play’s security vetting, are actually malware spying for the North Korean government.

The malware has been named KoSpy by Lookout, the security firm who discovered it. In all 5 cases these apps are disguised as utility apps, designed to help with file management, software updates and, ironically, device security.

What were these apps looking for?

Laptop showing security lock on screen

(Image credit: Shutterstock)
Keep your Android phone secure

From North Korean spy apps to active exploits, make sure you grab one of the best Android antivirus apps to keep your personal data secure.

But instead of actually helping you, these apps are secretly collecting sensitive personal data. Data collected include SMS messages, call logs, location data, files, nearby audio, keystrokes, Wi-Fi details and installed apps — with the added ability to take screenshots and record your screen.

All of those collection methods could capture some incredibly delicate personal details, only for it to be sent to servers controlled by North Korean intelligence workers.

Lookout claims it has “medium confidence” that the North Korean spy groups behind these apps have been previously tracked under the namesAPT37 (ScarCruft) and APT43 (Kimsuki).

The researchers noted that these apps seem to target English and Korean speakers, and have been found in at least 2 different Android app stores. Including Google Play and Apkpure. The affected apps include:

  • 휴대폰 관리자 (Phone Manager)
  • File Manager
  • 스마트 관리자 (Smart Manager)
  • 카카오 보안 (Kakao Security)
  • Software Update Utility

What happens now?

Android malware on phone

(Image credit: Shutterstock)

You probably wouldn’t know this problem when looking at the apps on their own. After all, a good spy network isn’t going to be caught out based on something stupid. Ars Technica notes that the developer email address is a standard Gmail address, with a privacy policy hosted on a blogspot account.

Ars notes that while the privacy policy page doesn’t raise any red flags, IP addresses hosting the command-and-control servers do. In fact they’ve been reported to have hosted at least 3 domains known to host infrastructure relating to North Korean intelligence operations since 2019.

Google also told the site that the “most recent app sample” was removed from Google Play before anyone could download them. They didn’t offer any further information, but mentioned that Google Play Protect can detect some malicious apps when you install them on Android — regardless of the source.

That said, this is another example of why people should be careful when installing apps on their phone — even if you’re installing directly from Google Play. Don’t install random apps that don’t offer any meaningful benefit, and always be sure to check which permissions your apps are asking for.

Only give them access to things they need, and not any random request the app makes. There’s no reason for a File Manager to need your location data, after all.

More from Tom's Guide

Tom Pritchard
UK Phones Editor

Tom is the Tom's Guide's UK Phones Editor, tackling the latest smartphone news and vocally expressing his opinions about upcoming features or changes. It's long way from his days as editor of Gizmodo UK, when pretty much everything was on the table. He’s usually found trying to squeeze another giant Lego set onto the shelf, draining very large cups of coffee, or complaining about how terrible his Smart TV is.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Green skull on smartphone screen.
Hackers are using the Amazon Appstore to spread malware — delete this malicious app now
DeepSeek logo on smartphone in front of merging US and Chinese flags
DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
Green skull on smartphone screen.
Only 3 of the top 150 Android apps can detect reverse engineering tool Frida — here's why that's bad
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
An image of a Google Android robot
Google blocked over 2.5 million suspicious Android apps from the Play Store last year
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in Android Phones
Try Galaxy home screen on iPhone 16 Pro Max
You can now try Samsung's latest One UI 7 software on your iPhone — here's how
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
The camera assembly on the Google Pixel 9
The latest Google Pixel update is breaking fingerprint scanners — but there may be a fix
Google Pixel 9a render
Google Pixel 9a will have to fix one crucial thing to hold off its low-cost rivals
Samsung Galaxy S25 Edge back
Samsung Galaxy S25 Edge price comes into focus with latest leak
Google Pixel 5 review
Google Pixel 10 lineup leaked in new renderings — here's what they look like
Latest in News
Try Galaxy home screen on iPhone 16 Pro Max
You can now try Samsung's latest One UI 7 software on your iPhone — here's how
Asus ROG Ally X
Xbox handheld reportedly being made with Asus — all to take on Steam Deck
A person typing on a laptop with warning messages displayed on screen
240 million Windows users under attack — update your PC now before hackers strike
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
Shokz OpenRun Pro 2 headphones
Samsung may take on Shokz and launch a set of Galaxy bone conduction headphones
galaxy z fold 6 vs. Galaxy s24 ultra
Samsung Galaxy Z Fold 7 tipped for a massive camera upgrade — here's what we know