Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

"We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers," the pair wrote. "Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims."

The Kaspersky duo said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions. Some of the apps where the pair uncovered malware are still available to download, including food delivery app ComeCome and AI chat apps AnyGPT and WeTink.

The malware in question uses optical character recognition (OCR) to review a device's photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says "This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace."

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss
Établi 2mo | 5 févr. 2025, 22:20:16


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

Assassin’s Creed Shadows has reached 2 million players, Ubisoft says

Assassin’s Creed Shadows may be shaping up to be the hit Ubisoft needed. On

22 mars 2025, 23:10:02 | Engadget
What to read this weekend: A historical horror classic in the making, and an ex-Facebook employee’s tell-all

These are the recently released titles that belong on your reading list. This week, we picked up Stephen Graham Jones’ The Buffalo Hunter Hunter, Sarah Wynn-Williams’ Careless Peo

22 mars 2025, 20:40:18 | Engadget
The FCC is investigating whether Huawei, other Chinese companies are evading US ban

The US Federal Communications Commission has launched what it describes as a "

22 mars 2025, 16:10:25 | Engadget
Amazon Spring Sale 2025: Everything to know so far and early tech deals from Apple, Bose, Sonos and others

We're still a few months out from the big Amazon Prime Day that typically happens in July, but the online retail giant is having yet another big sale to usher in spring. The

22 mars 2025, 16:10:24 | Engadget
Joint studies from OpenAI and MIT found links between loneliness and ChatGPT use

New studies from OpenAI and MIT Media Lab found that, generally, the more time users spend talking to ChatGPT, the lonelier they feel. The connection was made as part of

21 mars 2025, 21:30:19 | Engadget
Perplexity AI says it would rebuild TikTok's algorithm and add Community Notes features

Earlier this year, with a TikTok ban looming, Perplexity AI threw

21 mars 2025, 21:30:18 | Engadget