Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

"We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers," the pair wrote. "Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims."

The Kaspersky duo said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions. Some of the apps where the pair uncovered malware are still available to download, including food delivery app ComeCome and AI chat apps AnyGPT and WeTink.

The malware in question uses optical character recognition (OCR) to review a device's photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says "This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace."

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss
Utworzony 21d | 5 lut 2025, 22:20:16


Zaloguj się, aby dodać komentarz

Inne posty w tej grupie

Atari’s side-scrolling Breakout reboot arrives on March 25

Proving that truly no IP is safe from modern reboot

25 lut 2025, 17:40:10 | Engadget
Paramount+ adds 50 classic MTV Unplugged episodes

If you're a music fan of a certain age, there's a good chance MTV Unplugged has special place in your heart. With the first episode airing in 1989, over the decades the series has produced some of

25 lut 2025, 17:40:09 | Engadget
UK creatives protest AI copyright law changes with silent album and campaign

British creatives are speaking out against the government's proposed changes to copyright law. Take Kate Bush, Annie Lennox and Ben Howard, who join over 1,000 musicians in releasing a protest albu

25 lut 2025, 17:40:08 | Engadget
Philips Hue Sync now available on LG smart TVs, eliminating the need for a control box

The Philips Hue Sync app is now available for many LG televisions, allowing synchronization between smart lights and TV screens. This eliminates the need for one of those

25 lut 2025, 17:40:07 | Engadget
Clicks is finally releasing its keyboard add-on for some Android phones

First announced at CES 2024, the Clicks physical keyboard add-on for iPhones

25 lut 2025, 17:40:06 | Engadget
OnePlus is delaying the Watch 3 launch because of a typo

One thing writers and multinational consumer electronics corporations have in common is we both need a good editor. Or, failing that, at least a good spell-checker. OnePlus somehow missed that step

25 lut 2025, 17:40:05 | Engadget