Mobile Malware attack used Store apps and OCR to steal cryptocurrency recovery codes
#1
Information 
Quote:Malicious applications that are uploaded to Google's Play Store or Apple's App Store continue to be a problem for users worldwide. Google said that it blocked more than 2.3 million risky Android apps in 2024 alone.

Kaspersky security researchers have uncovered a recent malware attack. The goal of SparkCat, that is the name Kaspersky gave the malware, was to obtain cryptocurrency recovery codes.

The details:
  • Threat actors managed to upload apps to Google Play and App Store.
  • Apps were also distributed through unofficial channels.
  • The apps were embedded with a malicious SDK.
  • SparkCat has been active since at least April 2024.
Kaspersky says that infected apps on Google Play were downloaded more than 240,000 times by users. The malware would install an OCR plugin after launch to scan images on infected devices for recovery codes.

Good to know: Cryptocurrency recovery codes may be used to gain access to wallets. Discovered codes were sent to remote servers for processing.

Kaspersky mentions few of the application names and how they were advertised on Google Play. The app ComeCome-Chinese Food Delivery showed professional looking screenshots of the application. It was downloaded more than 10,000 times according to Kaspersky and popular in Indonesia and the United Arab Emirates.

Another app mentioned by Kaspersky is ChatAI. It had more than 50,000 downloads on Google Play. The number of downloads from unofficial sources is unknown.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sysinternals Suite 4.09.2026
Changes in 4.09.202...harlan4096 — 06:57
AnyDesk 9.7.0 for Windows
Version 9.7.0 for ...harlan4096 — 06:56
NVIDIA launches DLSS 4.5 Dynamic Multi ...
DLSS 4.5 Dynamic Fra...harlan4096 — 06:55
Google Chrome 146 Adds Device Bound Sess...
Google has introdu...harlan4096 — 06:54
WhatsApp is rolling out long-overdue use...
If you use the pop...harlan4096 — 06:53

[-]
Birthdays
Today's Birthdays
avatar (36)Kiran78
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>