North Korean APT Abuses Google's Find Hub to Remotely Wipe Devices

Middle-aged Caucasian man using a smartphone while standing on a city street at dusk or night, illustrating mobile technology and connectivity in urban environments.

A North Korean state-sponsored hacking group has been found weaponizing a legitimate Google feature to conduct destructive attacks. Security researchers at Genians Security Center identified a novel campaign by the KONNI group (also known as APT37 and linked to Kimsuky) where attackers abused Google’s “Find Hub” service to remotely track and factory-reset victims’ Android devices.

The attack, which marks the first known abuse of this feature by an APT group for destructive purposes, begins with a sophisticated spear-phishing operation. The KONNI attackers, often impersonating psychological counselors or human rights activists supporting North Korean defectors, trick victims into installing malware on their PCs. This initial compromise allows the attackers to exfiltrate sensitive data, including the Google account credentials saved in the victim’s browser.

First State-Sponsored Abuse of Find Hub

Once in possession of the Google account credentials, the attackers log into the victim’s account and access the “Find Hub” service (formerly “Find My Device”). This legitimate Google feature is intended to help users locate, lock, or erase a lost or stolen phone. The KONNI group, however, uses it for espionage and destruction.

Researchers observed attackers using the Find Hub’s location-tracking feature to monitor their targets. In one scenario documented by Genians, after confirming the victim was away from their device using GPS tracking, the attackers would trigger the “factory reset” option, remotely wiping all data from the phone. The attacker executed the wipe commands three times in some cases, which prevented recovery and kept victims locked out of their devices for extended periods.

This action immediately silences all notifications on the device, creating a critical window of opportunity. During this “silent” period, the attackers would then use the victim’s compromised KakaoTalk messenger account (a popular app in South Korea) to propagate malicious “stress-relief” apps to the victim’s trusted contacts, spreading the infection before the original owner even realized their phone had been erased.

No Security Flaw, But Credential Theft

Google confirmed the attack does not exploit a security flaw in Android or Find Hub, but rather relies on credential theft. The company urged users to enable two-step verification or passkeys to protect their accounts. Genians Security Center linked the campaign to KONNI, a group with overlapping targets and infrastructure with Kimsuky and APT37, all recognized as state-sponsored threat actors operating under the direction of the North Korean regime.

The Multilateral Sanctions Monitoring Team (MSMT), established under UN Security Council resolutions, recently released a report confirming that KONNI and Kimsuky are separate but closely associated groups, both operating under the sanctioned 63 Research Center in North Korea.

Sources: BleepingComputer, Genians Security Center, Dark Reading.

By the ID Tech Editorial Team