Individuals who escaped the territories of North Korea were targeted by malicious applications that were available on Google Play Store.
Reports have it that several apps made available on the Android digital distribution platform carried a malware that specifically targeted North Korean defectors. It was recently discovered by the cybersecurity company McAfee and was also found targeting journalists from the reclusive state.
The intrusive campaign was attributed to a hacker group that McAfee named the Sun Team and was characterized by injecting a spyware through installing malicious apps from the Play Store. In a recent blog, McAfee identified at least three apps, that were labeled “unreleased," to have been used in the surveillance. Two of the apps were marketed as an app locker while the other was disguised as a food-related software.
At the time of McAfee blog’s publication, the company revealed that the Sun Team hackers are “still actively trying to implant spyware on Korean victims’ devices.” Meanwhile, this particular report is the second surveillance campaign discovered to be perpetrated by the same group and had a very similar mode of operations.
The hidden spyware is activated once installed in an Android device. “Once the malware is installed, it copies sensitive information including personal photos, contacts, and SMS messages and sends them to the threat actors,” McAfee added.
Since the malware was discovered early, McAfee said the reported cases of surveillance through this campaign were relatively minimal and were only “about 100 infections from Google Play.”
Per McAfee’s research, the malware was in use last year. The hackers gather victims through a message campaign sent around via Facebook and with a “fake profile.”
It was found that the malware was able to remain active on Google Play for two months but was eventually taken down following detection. Naturally, Sun Team’s spyware was programmed to collect information and place it on cloud storage sites like Dropbox.
As always, smartphone users are advised to be very cautious when installing apps even if they are hosted on legitimate platforms such as the Play Store.


MongoDB Q1 FY2027 Earnings Beat Expectations, Raises Full-Year Outlook
Meta Subscription Push Could Add Billions in Recurring Revenue, Says Rosenblatt
Mega IPOs Like SpaceX and OpenAI Could Reshape S&P 500 and Nasdaq 100 Portfolios in 2026
Huawei Chip Breakthrough Sparks Rally in Chinese Semiconductor Stocks
PDG Explores $1 Billion Sale of China Data Center Assets
Samsung Union Dispute Escalates Over Semiconductor Bonus Vote
Morgan Stanley Names Top AI Security and Data Center Stocks for 2026
Marvell Stock Rises After Record Q1 FY2027 Earnings Fueled by AI Demand
Autodesk Beats Q1 Estimates, Acquires MaintainX for $3.6 Billion
Samsung to Invest $1.5 Billion in Vietnam Semiconductor Testing Plant by 2027
SpaceX Starship V3 Test Flight Boosts IPO Momentum Ahead of Historic Market Debut
Blue Origin New Glenn Rocket Explodes During Launch Pad Test, Delaying Space Ambitions
SK Hynix Joins $1 Trillion Club as AI Chip Demand Fuels Stock Surge
SoftBank to Invest €75 Billion in France AI Data Center Expansion by 2031
SpaceX IPO Hype Raises Questions as Many Major Stock Debuts Underperform Market
US Quantum Stocks Surge After $2 Billion Government Investment 



