Discover Top-Quality Products at Stellar Prices – Every Time You Shop!

Kaspersky researchers find screenshot-reading malware on the App Store and Google Play

Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.

“We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers,” the pair wrote. “Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims.” They said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions.

On February 6, Kaspersky updated its report to note that the affected apps had been deleted from the App Store. Apple confirmed that it had removed the 11 apps, adding that the applications shared code with 89 apps that previously had been rejected or removed from the store.

The malware in question uses optical character recognition (OCR) to review a device’s photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace.”

Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.

Update, February 6, 2025, 5:15PM ET: Revised to note an update from the Kaspersky report about the apps being removed from the App Store, as well as additional context from Apple.

Trending Products

0
Add to compare
- 11%
Thermaltake V250 Motherboard Sync ARGB ATX Mid-Tower Chassis with 3 120mm 5V Addressable RGB Fan + 1 Black 120mm Rear Fan Pre-Installed CA-1Q5-00M1WN-00

Thermaltake V250 Motherboard Sync ARGB ATX Mid-Tower Chassis with 3 120mm 5V Addressable RGB Fan + 1 Black 120mm Rear Fan Pre-Installed CA-1Q5-00M1WN-00

Original price was: $89.99.Current price is: $79.99.
0
Add to compare
- 20%
Dell KM3322W Keyboard and Mouse

Dell KM3322W Keyboard and Mouse

Original price was: $24.99.Current price is: $19.99.
0
Add to compare
- 20%
Sceptre Curved 24-inch Gaming Monitor 1080p R1500 98% sRGB HDMI x2 VGA Construct-in Audio system, VESA Wall Mount Machine Black (C248W-1920RN Sequence)

Sceptre Curved 24-inch Gaming Monitor 1080p R1500 98% sRGB HDMI x2 VGA Construct-in Audio system, VESA Wall Mount Machine Black (C248W-1920RN Sequence)

Original price was: $99.97.Current price is: $79.97.
0
Add to compare
- 19%
Lenovo V14 Gen 3 Business Laptop, 14″ FHD Display, i7-1255U, 24GB RAM, 1TB SSD, Wi-Fi 6, Bluetooth, HDMI, RJ-45, Webcam, Windows 11 Pro, Black

Lenovo V14 Gen 3 Business Laptop, 14″ FHD Display, i7-1255U, 24GB RAM, 1TB SSD, Wi-Fi 6, Bluetooth, HDMI, RJ-45, Webcam, Windows 11 Pro, Black

Original price was: $739.00.Current price is: $599.00.
.

We will be happy to hear your thoughts

Leave a reply

FindStellarDeals
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart