DocSwap Malware Targets Android Users Via QR Codes

18 Dec 2025

A new variant of Android malware, named DocSwap, has been identified as part of a campaign linked to North Korean threat actors. This malware is distributed through QR codes embedded in phishing sites disguised as the logistics company, CJ Logistics, based in Seoul.

Malware Distribution Method

Threat actors have employed QR codes and pop-up notifications to deceive victims into downloading a fake delivery tracking or security module app, namely SecDelivery.apk. This trojanized app requests multiple permissions, such as storage, internet access, and package installation. It operates by downloading and decrypting an embedded payload, registering a delivery service component, and launching an authentication process similar to OTP systems.

Upon installation, DocSwap becomes capable of keystroke logging, audio capture, and much more, while masquerading as a legitimate CJ Logistics tracking page visible to the victim.

Capabilities and Implications

According to ENKI, a South Korean cybersecurity firm, the malware showcases advanced techniques, including dynamic decryption of internal resources and adopting diverse evasive tactics. The scope of its operations is broadened by its ability to exfiltrate sensitive data like SMS, call logs, and contacts.

DocSwap seems to be a part of broader phishing schemes targeting Korean platforms, utilizing fake pages of well-known services such as Naver and Kakao to gather credentials. Additionally, it has been found disguised as legitimate apps, such as a P2B Airdrop application and a compromised VPN service, signaling a trend towards sophisticated app repackaging tactics.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6932165
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1505701
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
632587
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
473731
downloads

News and reviews for Mobile Android

Androidify Brings Custom Bots to Wear OS Watches

Google's Androidify now supports Wear OS: users can create Android bots from selfies and set them as watch faces.

Read more

Discounted App Deals Unveiled for Android Games

Major app deals launched via Google Play: discounted top-tier games for Android users, just in time for the holiday season.

Read more

Android 16 QPR3 Adds Real-Time Location Indicator

Android 16 QPR3 introduces a blue dot indicating app location use, enhancing privacy controls for users.

Read more

Google Play Launches Holiday Android Deals on Top Games

Google Play's annual Android deals began today, offering discounts on popular titles ahead of the holidays.

Read more

Android 16 QPR3 Enhances Location Privacy Notifications

Android 16 QPR3 beta adds new location tracking indicator, increasing user privacy control.

Read more

Duolingo Faces Criticism Over Monetization Shifts in 2025

Duolingo's monetization and AI-first strategy under scrutiny in 2025, prompting users to explore alternatives.

Read more

Android 16 QPR3 Beta 1 Adds Location Use Alerts

Google's Android 16 QPR3 Beta 1 enhances app transparency with location use alerts on Pixel 6+ devices.

Read more

Microsoft Introduces Remote Lock for Windows 11 via Phone Link

Microsoft's Phone Link adds remote lock, screen mirroring, and more for Android users and Windows 11.

Read more

Play Store Restores Uninstall Button for System Apps

Google reverts Play Store change, restoring the uninstall updates button for system apps to enhance user convenience.

Read more

DocSwap Malware Targets Android Users Via QR Codes

DocSwap malware, linked to North Korea, targets Android users using QR codes to mimic CJ Logistics.

Read more