Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S9005
MITRE ATT&CK Malware

DocSwap (S9005)

ShareXLinkedInRedditHN

[DocSwap](https://attack.mitre.org/software/S9005) is an Android malware first identified in 2025, and attributed to [Kimsuky](https://attack.mitre.org/groups/G0094). [DocSwap](https://attack.mitre.org/software/S9005)’s name is a combination of its Korean name “문서열람 인증 앱” (Document Viewing Authentication App) and a phishing page masquerading as CoinSwap at the C2 address. Based on [DocSwap](https://attack.mitre.org/software/S9005)’s name and Korean-language strings, [DocSwap](https://attack.mitre.org/software/S9005) potentially targets mobile device users in South Korea. Several variants of [DocSwap](https://attack.mitre.org/software/S9005) exist; one of the latest samples indicates that the adversary added a native decryption function that decrypts an internal APK.(Citation: EnkiWhiteHat_KimsukyDOCSWAP_Dec2025)(Citation: S2W_DocSwap_Mar2025)

Platforms: Android

▪Techniques implemented (27)

T1406Obfuscated Files or InformationT1429Audio CaptureT1417.001KeyloggingT1426System Information DiscoveryT1575Native APIT1541Foreground PersistenceT1420File and Directory DiscoveryT1636.004SMS MessagesT1422.002Wi-Fi DiscoveryT1422System Network Configuration DiscoveryT1512Video CaptureT1627Execution GuardrailsT1636.003Contact ListT1616Call ControlT1636.002Call LogT1453Abuse Accessibility FeaturesT1544Ingress Tool TransferT1624.001Broadcast ReceiversT1430Location TrackingT1655.001Match Legitimate Name or LocationT1630.002File DeletionT1660PhishingT1636.005AccountsT1437.001Web ProtocolsT1533Data from Local SystemT1646Exfiltration Over C2 ChannelT1418Software Discovery
S9005on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.