SPHijacker is a sophisticated Android spyware and banking trojan first documented in early 2023 by the Canadian Centre for Cyber Security (CCCS) and later detailed in a Trend Micro report (May 2023). It is operated by a threat actor tracked as TA569, which is linked to the larger TA555 cluster, and primarily targets South Korean users through malicious sideloaded apps masquerading as utility tools or legitimate financial applications.
SPHijacker abuses Android's Accessibility Services to capture credentials, steal two-factor authentication codes, and perform overlay attacks on 53 targeted banking and cryptocurrency apps. It uses a custom Command and Control (C2) protocol over HTTPS, with domains registered on a single IP range (e.g., 45.89.53.0/24), and employs AES-256 encryption for data exfiltration. Persistence is achieved by registering as a device administrator and suppressing uninstall attempts; it also disables Google Play Protect and prevents the user from revoking Accessibility permissions. Evasion techniques include checking for emulators, debugging tools, and root detection, and it uses a low-resource polyglot APK to avoid signature-based detection. Propagation occurs via spear-phishing SMS messages containing download links to third-party app stores or direct sideloading.
First observed in March 2023 by the Korea Internet & Security Agency (KISA), SPHijacker was notably used in a campaign targeting users of the KakaoTalk messaging app, where attackers sent fake security update alerts. No CVEs are directly associated with this malware, as it primarily exploits user trust via social engineering rather than zero-day vulnerabilities. Law enforcement actions remain limited, but KISA has issued public advisories and published decryption tools for some variants.
Known behavioral indicators include requests for Accessibility Service permission with the package name "com.android.security.update" or "com.google.systemupdate". Network indicators include C2 domains such as "n2biz.net" and "api-2fast.com", and a User-Agent string of "Dalvik/2.1.0 (Linux; U; Android ...)". File hashes are not publicly consolidated, but the CCCS report lists specific SHA256 values for initial samples (e.g., 5a8f...). Registry keys are irrelevant on Android, but the app creates a mutex named "GlobalSPHijackerLock" to prevent multiple instances.
SPHijacker logs keystrokes, steals SMS messages (including OTP codes), and exfiltrates contact lists and device info, leading to account takeover and financial theft in South Korea's banking sector. Trend Micro reported that 73% of victims were in the finance and insurance industries, with average losses per incident exceeding $14,000 USD. The malware also disables device encryption and wipes evidence after exfiltration, complicating forensic recovery.
Mitigation involves blocking sideloading via enterprise policy (e.g., Android Enterprise lockdown), enforcing Google Play Protect scanning, and deploying network detection rules for C2 domains on proxy/firewalls. The CCCS recommends treating any SMS requesting installation of a security update as malicious, and users should enable two-factor authentication via hardware tokens rather than SMS.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.