DocSwap Android malware variant with encrypted APK loading and RAT capabilities
Malware Activity
Summary
Hide ▲
Show ▼
A new DocSwap Android malware variant now uses encrypted APK loading to gain RAT capabilities on Android devices. Victims are lured through QR-code phishing and fake delivery tracking flows that push them to install SecDelivery.apk. Once installed, the malware can collect device data and accept remote commands, increasing the risk of device compromise and credential theft.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
BTMOB Android RAT no-code builder malware activity
Malware Activity
H score28
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
Latest development: 29.05.2026 00:10
BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.
BirdCall Android spyware variant
Malware Activity
H score4
First: 05.05.2026 12:04
Last: 05.05.2026 12:04
Sources 1
About this happening:
The BirdCall Android spyware variant expanded a known Windows backdoor into a mobile surveillance tool with file exfiltration and device reconnaissance capabilities. I...
BirdCall Android spyware variant
Malware ActivityAbout this happening: The BirdCall Android spyware variant expanded a known Windows backdoor into a mobile surveillance tool with file exfiltration and device reconnaissance capabilities. I...
NoVoice Android malware hidden in Google Play apps
Malware Activity
H score21
First: 01.04.2026 21:07
Last: 01.04.2026 21:07
Sources 1
About this happening:
NoVoice Android malware was found hidden in more than 50 Google Play apps, exposing at least 2.3 million downloads to compromise. After installation, it used old And...
NoVoice Android malware hidden in Google Play apps
Malware ActivityAbout this happening: NoVoice Android malware was found hidden in more than 50 Google Play apps, exposing at least 2.3 million downloads to compromise. After installation, it used old And...
Perseus Android note-stealing and remote-control malware activity
Malware Activity
H score21
First: 19.03.2026 12:13
Last: 19.03.2026 12:13
Sources 1
About this happening:
The Perseus Android malware is now being used to inspect user notes for secrets, creating theft risk for passwords, recovery phrases, and financial data. It is als...
Perseus Android note-stealing and remote-control malware activity
Malware ActivityAbout this happening: The Perseus Android malware is now being used to inspect user notes for secrets, creating theft risk for passwords, recovery phrases, and financial data. It is als...
Timeline
-
18.12.2025 09:43 2 articles · 6mo ago
Kimsuky-linked DocSwap QR-phishing campaign disclosed
Initial DisclosureKimsuky-linked operators distributed a new DocSwap Android malware variant through QR-code phishing pages impersonating CJ Logistics and other delivery-themed services, using notification pop-ups and a fake shipment-tracking flow to push installation of SecDelivery.apk. After installation, the malware decrypts an embedded APK, registers com.delivery.security.MainService, and provides RAT capabilities for keystroke logging, audio capture, camera control, command execution, file operations, and collection of location, SMS messages, contacts, call logs, and installed apps. Related artifacts also included a trojanized BYCOM VPN package and phishing pages impersonating Naver and Kakao.
Show sources
- Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App — thehackernews.com — 18.12.2025 09:43
- Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App — thehackernews.com — 18.12.2025 09:43