Several Google Play Store apps, targeting English and Korean speakers, were found to be collecting sensitive user information and technical data for North Korean agents. The apps contained malware and spyware which bypassed Google’s security checks. The spyware was attributed to the North Korean APT group ScarCruft and is relatively new. Users are being advised to download apps from trusted sources and check app permissions and shared data.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.