Microsoft Word - Dragon Messenger_eng.docx
ID: a14dc289-d00f-47af-befc-947be0962bc4
STIX ID: report--a14dc289-d00f-47af-befc-947be0962bc4
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-11-11
Last Modified Date: 2019-11-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary: ESRC describes "Dragon Messenger," a Geumseong121 mobile APT campaign that spread malicious Android apps (one briefly on Google Play) disguised as a charity for North Korean defectors and as secure messengers, using social engineering via KakaoTalk/Facebook/YouTube; the apps harvest credentials (stored in plaintext), exfiltrate SMS/contacts, can eavesdrop on calls and capture KakaoTalk content, reuse code/path artifacts from prior Geumseong121 samples, and include cryptographic/file manager components and provided file-hash IoCs.
