• News/
  • https://www.bleepingcomputer.com/news/security/apt37-hackers-abuse-google-find-hub-in-android-data-wiping-attacks/

APT37 hackers abuse Google Find Hub in Android data-wiping attacks

BleepingComputer
·
Bill Toulas
·
Published Nov 11, 2025
·
Updated

North Korean hackers are abusing Google’s Find Hub tool to track the GPS location of their targets and remotely reset Android devices to factory settings. The attacks are primarily targeting South Koreans, and start by approaching the potential victims over KakaoTalk messenger - the most popular instant messaging app in the country. South Korean cybersecurity solutions company Genians links the malicious activity to a KONNI activity cluster, which "has overlapping targets and infrastructure with Kimsuky and APT37." KONNI typically refers to a remote access tool that has been linked to attacks from North Korean hackers in the APT37 (ScarCruft) and Kimsuky (Emerald Sleet) groups that targeted multiple sectors (e.g., education, government, and cryptocurrency). According to Genians, the KONNI campaign infects computers with remote access trojans that enable sensitive data exfiltration. Wiping Android devices is done to isolate victims, delete attack traces, delay recovery, and silence security alerts. Specifically, the reset disconnects victims from KakaoTalk PC sessions, which the attackers hijack post-wiping to spread to their targets’ contacts. The KONNI campaign analyzed by Genians targets victims via spear-phishing messages that spoof South Korea’s National Tax Service, the police, and other agencies. Once the victim executes the digitally signed MSI attachment (or a .ZIP containing it), the file invokes an embedded install.bat and an error.vbs script used as a decoy to mis...

Read full article

Affected Software

2 affected components
Google Find Hub
Android Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how North Korean hackers are exploiting Google's Find Hub tool to conduct Android data-wiping attacks.

2

What security implications are discussed in the article?

The article highlights concerns about unauthorized tracking and remote wiping of Android devices through a legitimate Google tool.

3

Who are the primary targets of these attacks?

The attacks primarily target individuals in South Korea.

4

What products or software are affected by these attacks?

The affected products include Google Find Hub and Android devices.

5

How do the hackers initiate their attacks according to the article?

The hackers initiate their attacks by approaching victims through social engineering tactics.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203