Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

“We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers,” the pair wrote. “Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims.”

The Kaspersky duo said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions. Some of the apps where the pair uncovered malware are still available to download, including food delivery app ComeCome and AI chat apps AnyGPT and WeTink.

ADVERTISEMENT

Advertisement

The malware in question uses optical character recognition (OCR) to review a device’s photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace.”

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

Related Posts

Sonos will cut ‘about 200’ jobs in restructuring

Sonos is embarking on a restructuring plan that will eliminate about 200 positions at the company. Interim CEO Tom Conrad announced the news in a call with the team, then…

Read more

Warner Bros is sharing select movies for free on YouTube

[embedded content] Over the past several weeks, Warner Bros. Entertainment has been uploading a selection of full movies to a playlist on YouTube. It’s an odd move, considering parent Warner…

Read more

Google is reportedly changing course on its diversity initiatives, too

Google is changing its tune around efforts to hire employees from historically underrepresented backgrounds, according to a new report from The Wall Street Journal. The company reportedly announced that it…

Read more

Reddit blames ‘bug’ after banning more than 90 NSFW subreddits

Reddit briefly banned dozens of subreddits without warning on Wednesday due to a “bug” that affected scores of NSFW communities on the site. Redditors were told the subreddits were banned…

Read more

Every Generation Of Porsche 911 GT3 RS, Ranked By Top Speed

The Porsche 911 GT3 RS is Porsche’s most powerful normally aspirated 911, as well as its most track-focused car. The 911 GT3 RS, designed as an enhancement of the 911…

Read more

WolfEye Studios partners with Neowiz on new sci-fi action-RPG

Neowiz announced today that it has partnered with developer WolfEye Studios on the latter’s second title, an unnamed first-person action-RPG set in a retrofuturistic setting. Neowiz will distribute the game…

Read more

Leave a Reply