DocSwap

MITRE ATT&CK: S9005 View on attack.mitre.org

Aliases: DocSwap

Malware type
trojan, spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:29:24

Targeted industries: financial-services

Targeted regions: country_code:kr

Context

DocSwap is an Android malware first identified in 2025, and attributed to Kimsuky. DocSwap’s name is a combination of its Korean name “문서열람 인증 앱” (Document Viewing Authentication App) and a phishing page masquerading as CoinSwap at the C2 address. Based on DocSwap’s name and Korean-language strings, DocSwap potentially targets mobile device users in South Korea. Several variants of DocSwap exist; one of the latest samples indicates that the adversary added a native decryption function that decrypts an internal APK.

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Audio Capture (attack-pattern)
  • Keylogging (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Foreground Persistence (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Contact List (attack-pattern)
  • Call Control (attack-pattern)
  • Call Log (attack-pattern)
  • Abuse Accessibility Features (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • Location Tracking (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • File Deletion (attack-pattern)
  • Phishing (attack-pattern)
  • Accounts (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)

Reports & references

  • MITRE ATT&CK — S9005 (report)
  • medium.com — Detailed Analysis Of Docswap Malware Disguised As Security Document Viewer 218A728C36Ff (report)
  • enki.co.kr — Kimsuky Distributing Malicious Mobile App Via Qr Code (report)

External references