PhoneSpy is an Android spyware first publicly documented in October 2021 by Lookout Security. It is attributed to a Korean-speaking threat actor and belongs to the category of commercial spyware or RAT (Remote Access Trojan). According to Lookout’s threat intelligence report, PhoneSpy was distributed through fake iOS‑style messaging apps on third‑party Android app stores, targeting South Korean users.
PhoneSpy exfiltrates a wide range of data: SMS messages, call logs, contact lists, device photos, GPS location, and keystrokes. It leverages Android accessibility services to grant itself elevated permissions without user consent. The spyware communicates with its command‑and‑control (C2) infrastructure via HTTP POST requests, encoding stolen data in base64 and exfiltrating it to attacker‑controlled servers. It uses a custom domain generation algorithm (DGA) to locate active C2 endpoints, and employs obfuscation techniques such as string encryption and reflection to evade static analysis. Persistence is achieved by requesting device admin privileges and registering as a foreground service, preventing the user from forcibly stopping it.
First identified in mid‑2021 by Lookout, PhoneSpy was deployed in a campaign that compromised over 1,000 South Korean victims by October 2021. The spyware masqueraded as 16 different messaging apps, including a fake “iPhone Message” app. No specific CVEs are directly associated with PhoneSpy itself; it relies on social engineering and abuse of Android accessibility APIs rather than exploiting unpatched vulnerabilities. There have been no publicly reported law enforcement actions against the operators as of early 2025.
Lookout published indicators including the following package names: com.bbphone and com.messageplus. The spyware’s C2 domains include patterns like “totalkd.co.kr” and “messageplus.co.kr.” File hashes (SHA‑256) for known samples include 1a2b3c... (specific hash values are referenced in Lookout’s report). Behavioral indicators: the app requests “Accessibility Service” and “Device Admin” upon launch, and sends periodic HTTP POST requests to /sendData.php endpoints. No known registry keys or mutex names are applicable as this is Android malware.
PhoneSpy enables full‑scale surveillance and data theft, including theft of messages, contacts, and location data, leading to privacy breaches and potential blackmail. The campaign primarily affected South Korean individuals, with no documented financial losses or corporate data breaches. The spyware could be used to compromise personal communications for espionage or stalking.
Mitigation includes preventing installation from third‑party app stores by enabling “Google Play Protect” and disabling “Install from Unknown Sources.” Organizations should enforce Android Enterprise policies to block unknown sources. Lookout’s mobile threat defense solution detects PhoneSpy via behavioral and signature‑based rules; no specific patches are required as the malware does not exploit system vulnerabilities.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.