Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

"We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers," the pair wrote. "Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims."

The Kaspersky duo said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions. Some of the apps where the pair uncovered malware are still available to download, including food delivery app ComeCome and AI chat apps AnyGPT and WeTink.

The malware in question uses optical character recognition (OCR) to review a device's photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says "This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace."

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss
Létrehozva 20d | 2025. febr. 5. 22:20:16


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

The Morning After: How to follow Amazon’s hardware event tomorrow

Amazon doesn’t usually do device events in February, but in a year of turbulence, why not? The company is holding a presentation in New York, and, like in the past, Amazon won’t be livestreaming an

2025. febr. 25. 12:50:14 | Engadget
Tron: Catalyst hits consoles and PC on June 17

Tron: Catalyst, the follow-up to Tron: Identity and the next game from Bithell Games, is

2025. febr. 24. 23:10:14 | Engadget
Disney+ just dropped an explosive trailer for Andor season 2

It’s been well over two years, but the wait is almost over. The second season of Andor hits Disney+ on April 22. The platform

2025. febr. 24. 20:40:26 | Engadget