Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

"We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers," the pair wrote. "Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims."

The Kaspersky duo said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions. Some of the apps where the pair uncovered malware are still available to download, including food delivery app ComeCome and AI chat apps AnyGPT and WeTink.

The malware in question uses optical character recognition (OCR) to review a device's photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says "This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace."

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss
Created 2mo | Feb 5, 2025, 10:20:16 PM


Login to add comment

Other posts in this group

The Amazon Spring Sale 2025 is live: The best tech deals from Apple, Bose, Sonos, Anker and others

The Amazon Spring Sale has arrived, bringing a slew of discounts on household essentials, fashion, outdoor gear a

Mar 26, 2025, 1:11:11 AM | Engadget
The Pentagon warns government officials that Signal is being targeted by Russian hackers

As it turns out, including a reporter in your national security leader group chat about military strikes isn't the only way to compromise sensitive information on Signal. NPR

Mar 25, 2025, 10:50:04 PM | Engadget
Game Informer is back and so is its entire team

Gaming journalism stalwart Game Informer has risen from the ashes. More than thirty years afte

Mar 25, 2025, 10:50:03 PM | Engadget
Google releases Gemini 2.5 AI model for complex thinking

Google has the pedal to the metal on its AI development. Just a few months after the debut of

Mar 25, 2025, 8:30:37 PM | Engadget
Dreamhaven's Tabletop RPG party game Sunderfolk arrives on April 23

Sunderfolk, a game that borrows elements from tabletop games like Dungeons & Dragons and couch party games like Jackbox, has a launch date. The

Mar 25, 2025, 8:30:36 PM | Engadget
The UK could greenlight direct-to-phone satellite services this year

If you live in a rural area of the UK, you may soon be able to use your phone for satellite calls, messages and other standard data use. On Tuesday, the nation's telecom regulator, Ofcom,

Mar 25, 2025, 8:30:35 PM | Engadget
Vampire: The Masquerade - Bloodlines 2 is now slated to launch in October 2025

Vampire: The Masquerade - Bloodlines 2 has been delayed again. Publisher Paradox Interactive

Mar 25, 2025, 8:30:34 PM | Engadget