logo

Microsoft Word - Dragon Messenger_eng.docx

ID: a14dc289-d00f-47af-befc-947be0962bc4

STIX ID: report--a14dc289-d00f-47af-befc-947be0962bc4

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-11-11

Last Modified Date: 2019-11-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary: ESRC describes "Dragon Messenger," a Geumseong121 mobile APT campaign that spread malicious Android apps (one briefly on Google Play) disguised as a charity for North Korean defectors and as secure messengers, using social engineering via KakaoTalk/Facebook/YouTube; the apps harvest credentials (stored in plaintext), exfiltrate SMS/contacts, can eavesdrop on calls and capture KakaoTalk content, reuse code/path artifacts from prior Geumseong121 samples, and include cryptographic/file manager components and provided file-hash IoCs.