Skip to content
South Korea's LG Uplus Ramps Up AI-Powered Blocking of 'Zombie Phone' Malware Ahead ...

South Korea's LG Uplus Ramps Up AI-Powered Blocking of 'Zombie Phone' Malware Ahead ...

Finance.Biggo September 13, 2026

South Korea's LG Uplus is entering a 24-hour special response regime powered by its artificial intelligence (AI)-based security system ahead of the Chuseok holiday. With smishing texts impersonating package deliveries and malware distribution attempts surging during every major holiday, the carrier's strategy is to use its in-house technology to trace and block criminal organizations' command-and-control servers.

The company announced on the 13th that it will operate a dedicated monitoring team at its Magok office in Seoul through the end of this month, centered on its AI-based "Customer Harm Prevention Analysis System (Secure.AI+)." During this period, tracking and blocking of malicious app control servers will be intensified beyond normal levels.

During holiday periods, calls and texts impersonating delivery companies—typically claiming "please confirm your Chuseok gift delivery address"—are distributed en masse. On top of this, a rapidly growing tactic involves luring victims into installing malicious apps by enticing them to invest through unverified illegal investment sites or unofficial trading apps.

Once a malicious app is installed on a smartphone, the device is reduced to what is known as a "zombie phone." Criminal organizations can intercept or block incoming calls to the victim through remote control servers, and can even manipulate the caller ID of their own outgoing calls to display numbers such as 112 (South Korea's police emergency line) or 1301 (the prosecution service's main number). Victims are led to believe the call is genuinely from police or prosecutors, making them far more vulnerable to voice phishing.

LG Uplus explained that it is the only South Korean telecom carrier using Secure.AI+ to directly track malicious app control servers operated by voice phishing organizations. The company has established a hotline with police to immediately information when infections are confirmed, and will respond promptly to police requests for blocking.

When the company's internal analysis detects traces of a customer's device communicating with a malicious app control server, it alerts the customer to the risk via KakaoTalk notification messages. Customers who receive such alerts can seek consultation and necessary measures at their nearest police station or LG Uplus store. The company is also continuously training its AI on spam and smishing text patterns that frequently appear during holidays to improve blocking accuracy.

The core of this response effort is the emphasis on preemptive blocking rather than after-the-fact reporting. Whereas conventional spam filtering analyzes message content or caller ID patterns, Secure.AI+ goes further by tracing communication traces exchanged with criminal servers after a malicious app has been installed. This approach can reduce cases where infected devices are left unattended as "zombie phones" without the owner ever realizing the infection.

The company also issued precautionary guidance for customers. Users should not click on URLs contained in messages from unclear sources, and should immediately hang up on calls demanding app installation while impersonating customer service centers or public institutions. Customers are advised to regularly run security checks with smartphone antivirus apps, and if infection is suspected, to report it using a different mobile phone to the Korean National Police Agency's Integrated Reporting and Response Center for Telecommunications Financial Fraud (1394).

Hong Gwan-hee, Chief Information Security Officer (CISO and Executive Vice President) at LG Uplus, said: "LG Uplus will operate a 24-hour monitoring system before and after the Chuseok holiday and do its utmost to prevent customer harm. We urge customers who receive malicious app risk notification messages to immediately visit their nearest police station or LG Uplus store for the necessary measures."

Behind telecom carriers' aggressive adoption of AI for voice phishing response lies the increasingly sophisticated nature of criminal tactics. Beyond simple smishing such as delivery impersonation, the method of luring victims to illegal investment sites and then inducing malicious app installation makes it difficult for victims to recognize they have been exposed to crime. In particular, devices seized as zombie phones can be exploited for caller ID spoofing by criminal organizations, posing a significant risk of secondary damage.

This initiative also aligns with the trend of security capabilities emerging as a differentiating factor in the mobile telecommunications market. As carriers are increasingly expected to go beyond being mere network providers and take responsibility for customers' financial safety, LG Uplus is positioning its proprietary AI analysis system and police collaboration framework to strengthen its security competitiveness.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (2)

Countries (1)

Domains (1)