Kaspersky researchers discover screenshot-reading malware on the App Retailer and Google Play

Researchers from Kaspersky have recognized malware being distributed inside apps on each Android and iOS cellular storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation right into a malware marketing campaign, which they’ve dubbed SparkCat, that has probably been energetic since March 2024.

"We can’t affirm with certainty whether or not the an infection was a results of a provide chain assault or deliberate motion by the builders," the pair wrote. "A few of the apps, equivalent to meals supply providers, seemed to be reliable, whereas others apparently had been constructed to lure victims." They stated SparkCat is a stealthy operation that at a look seems to be requesting regular or innocent permissions.

On February 6, Kaspersky up to date its report to notice that the affected apps had been deleted from the App Retailer. Apple confirmed that it had eliminated the 11 apps, including that the functions shared code with 89 apps that beforehand had been rejected or faraway from the shop.

The malware in query makes use of optical character recognition (OCR) to evaluate a tool's photograph library, searching for screenshots of restoration phrases for crypto wallets. Based mostly on their evaluation, contaminated Google Play apps have been downloaded greater than 242,000 instances. Kaspersky says "That is the primary identified case of an app contaminated with OCR spyware and adware being present in Apple’s official app market."

Apple typically promotes the rigorous safety of the App Retailer, and whereas situations of malware showing have been uncommon, this discovery is a reminder that the walled backyard just isn’t impervious to assaults.

Replace, February 6, 2025, 5:15PM ET: Revised to notice an replace from the Kaspersky report in regards to the apps being faraway from the App Retailer, in addition to further context from Apple.

This text initially appeared on Engadget at https://www.engadget.com/cybersecurity/kaspersky-researchers-find-screenshot-reading-malware-on-the-app-store-and-google-play-211011103.html?src=rss

HOT news

Related posts

Latest posts

Bybit, Bitget, MEXC, Kucoin Apps ‘Faraway from Japanese App Retailer’

Apple has reportedly moved to dam Japanese customers from downloading the apps of the crypto exchanges Bybit, Bitget, MEXC, Kucoin, and Bitcastle. ...

BlackRock Expands Crypto Choices With Bitcoin ETP in Europe: Report

BlackRock – the world’s largest asset supervisor, is gearing as much as launch a Bitcoin-linked exchange-traded product (ETP) in Europe. This marks its first...

Defending the US from hackers apparently is not in Trump’s funds

Members of the Division of Homeland Safety's Cybersecurity and Infrastructure Safety Company (CISA) are being compelled to decide on between staying at their jobs...

Twister Money Developer Alexey Pertsev Granted Supervised Launch from Jail

Alexey Pertsev, a developer related to the cryptocurrency-mixing service Twister Money, is ready to be launched from pretrial detention on Friday, January 10, 2025,...

Berachain Worth Pumps After Mainnet Launch – Meme Index to Explode Subsequent?

Berachain’s (BERA) mainnet is lastly stay. The Layer-1 blockchain launched this morning, and the native BERA token jumped instantly. Merchants are excited, with many...

Want to stay up to date with the latest news?

We would love to hear from you! Please fill in your details and we will stay in touch. It's that simple!