Breaking
February 7, 2025

Screen reading malware found in iOS app stores for first time – and it might steal your cryptocurrency | usagoldmines.com


  • Apps delivering malware to users to steal crypto found on iOS app store
  • Some of these apps have thousands of installs across iOS and Android
  • The ‘SparkCat’ campaign has been active since March 2024

Crypto-stealing malware dubbed ‘SparkCat’ has been discovered on iOS and Android app stores, and is embedded with a ‘malicious SDK/framework for stealing recovery phrases for crypto wallets’.

A report from Kaspersky has identified malicious apps, some with upwards of 10,000 downloads, that scan the victims gallery to find keywords – if relevant images are found, they are then sent to a C2 server.

This is the first time a stealer has been found in Apple’s App store, and this is significant because Apple reviews every entry to ‘help provide a safe and trusted experience for users’ – so these malware-infected apps show that the review process is not as robust as it should be.

Although aimed at stealing cryptocurrency wallet recovery phrases, Kaspersky notes that the malware is ‘flexible enough’ to steal other sensitive data from victim’s galleries – here’s what we know.

Multiple malicious apps

The ‘SparkCat’ malware campaign was first discovered in late 2024, and is suspected to have been active since March 2024.

The first app Kaspersky identified was a Chinese food delivery app, ComeCome. The app had over 10,000 downloads and was based in Indonesia and the UAE. The app was embedded with malicious content, and contained OCR spyware which chose images from the infected devices to exfiltrate and send to the C2 server.

This wasn’t the only infected app though, and researchers found that infected apps available in Google Play had been downloaded a combined total of over 242,000 times. In 2024, over 2 million risky Android apps were blocked from the Play Store, including some which tried to push malware and spyware – so although Google is improving its protections, clearly some still make it through.

In the app store, some apps ‘appeared to be legitimate’, like the food delivery services, while others had apparently been built to ‘lure victims’. An example of this, researchers outlined, is a series of similar AI-featured ‘messaging apps’ by the same developer, including AnyGPT and WeTink.

It’s not clear whether these infections are deliberate actions by developers, or are a result of supply chain attacks, but the report does note that the “permissions that it requests may look like they are needed for its core functionality or appear harmless at first glance.”

“What makes this Trojan particularly dangerous is that there’s no indication of a malicious implant hidden within the app” Kaspersky adds.

Mitigating malware

If you have one of the infected apps installed on your device, Kaspersky of course recommends removing it and steering clear until a fix is released – the list of infected apps can be found here.

There is software that can help protect your device, like antivirus software – and as a key part of this malware in particular is the exfiltration of sensitive data through screenshots, the best advice is to avoid storing passwords, confidential documents, or sensitive information in your gallery.

Instead, check out the best password managers to securely store your information, as these present a much safer and convenient option to keeping your passwords in your photos. Make sure you don’t reuse passwords on multiple sites, and change your passwords regularly to avoid a breach.

There are some tricks to avoid malware apps, and considering that dangerous malware apps have been found to have been installed millions of times, it’s always best to be safe.

First of all, be wary of the warning signs. Go through the feedback and reviews – especially the negatives, as it’s likely someone else will have already flagged a bug. Be very suspicious of an app which asks for your existing social media credentials – as this could be criminals looking to hijack your account.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

iPhone SE 4 Launching as Soon as Next Week Juli Clover | usagoldmines.com

Mistral AI's 'Le Chat' Chatbot Now Available on iPhone Juli Clover | usagoldmines.com

AWS partners with Orbital Materials to boost carbon removal, cooling, and efficiency in data centers...

Apple's iPhone SE 4 might arrive as soon as next week, according to a new report jacob.krol@futurene...

Would you use Google Gemini if it fills with ads? erichs211@gmail.com (Eric Hal Schwartz) | usagoldm...

Best smart lighting 2025: Smart bulbs, string lights, outdoor, and more | usagoldmines.com

This TCL QLED Is One of the Best Budget-Friendly TVs I've Ever Used Daniel Oropeza | usagoldmines.co...

Five of My Favorite Cheap Storage Solutions Lindsey Ellefson | usagoldmines.com

The Two Biggest Mistakes Beginners Make on the Rowing Machine Beth Skwarecki | usagoldmines.com

Netflix Raises Prices in the UK Juli Clover | usagoldmines.com

Apple Removed Apps Infested With Screen Reading Malware Juli Clover | usagoldmines.com

White House budget proposal could shatter the National Science Foundation Eric Berger | usagoldmines...

Nintendo patent explains Switch 2 Joy-Cons’ “mouse operation” mode Kyle Orland | usagoldmines.com

Changing Your Passwords Isn't the Security Measure You Think It Is Jake Peterson | usagoldmines.com

Google Search App for iOS Now Supports Auto Dark Mode Juli Clover | usagoldmines.com

Leica's new iPhone camera grip could have been great, but has 3 frustrating drawbacks mark.wilson@fu...

This flexible and transparent microLED display eliminates mass transfer and laser welding processes ...

Apple built a super-cute, expressive robot lamp that is giving us major Pixar vibes jacob.krol@futur...

DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers Dan Goodin | usagoldmines.co...

How to Control an Android Phone From Your Computer Justin Pot | usagoldmines.com

Seven of My Favorite Money-Saving Meals Allie Chanthorn Reinmann | usagoldmines.com

Alleged Foldable iPhone Specs Detailed in Questionable Rumor Juli Clover | usagoldmines.com

Apple's New Invites App Hints at iOS 19's Rumored Redesign Joe Rossignol | usagoldmines.com

NYT Connections hints and answers for Friday, February 7 (game #607) | usagoldmines.com

NYT Strands hints and answers for Friday, February 7 (game #341) | usagoldmines.com

Quordle hints and answers for Friday, February 7 (game #1110) | usagoldmines.com

ChatGPT comes to 500,000 new users in OpenAI’s largest AI education deal yet Benj Edwards | usagoldm...

Meta torrented over 81.7TB of pirated books to train AI, authors say Ashley Belanger | usagoldmines....

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

This 4K laptop with RTX 4080 and 64GB RAM is a whopping $800 off | usagoldmines.com

How to Nap at Work (and Get Away with It) Jeff Somers | usagoldmines.com

Best Buy Is Giving Away a Free TV When You Buy One of These Massive Samsung LED TVs Daniel Oropeza |...

Microsoft reveals more on just how much it'll cost you to keep using Windows 10 | usagoldmines.com

Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk ...

Protection from COVID reinfections plummeted from 80% to 5% with omicron Beth Mole | usagoldmines.co...

The UK got rid of coal—where’s it going next? Gordon Feller | usagoldmines.com

You Need to Clean Your Humidifier More Than You Think Lindsey Ellefson | usagoldmines.com

Five Easy Ways to Hide Cords and Cables in Your Home Jeff Somers | usagoldmines.com

Disney Plus just lost 700,000 subscribers, but that won’t stop another price hike – far from it hami...

Nvidia out? DeepSeek pairs with banned Chinese tech giant to deliver unbelievably low pricing on AI ...

Google Chrome's Incognito mode is now more private in Windows 11 - and it's all thanks to Microsoft ...

Parrots can imitate meaningless behavior almost as well as humans Elizabeth Rayne | usagoldmines.com

Google’s Gemini rolls out ‘world’s best’ AI model, free of charge | usagoldmines.com

ChatGPT’s new AI search beats Google in this one thing | usagoldmines.com

Is the new AI-powered Alexa almost here? 6 things to know | usagoldmines.com

ASRock says it’s shifting out of China to avoid U.S. tariffs | usagoldmines.com

Warner Bros. Is Uploading Classic Movies to YouTube for Free Jake Peterson | usagoldmines.com

25 of the Best Romantic Comedies Streaming on Netflix Right Now Ross Johnson | usagoldmines.com

Apple Prototypes Tabletop Robot With Lifelike Movements Ahead of Rumored Launch by 2027 Joe Rossigno...

Google Pixel 9a: latest news, rumors, and everything we’ve heard so far | usagoldmines.com

Salesforce rival builds advanced project management into CRM | usagoldmines.com

Laptop makers, I’m begging you for this one simple feature | usagoldmines.com

Super Bowl LIX streaming and viewing options, ranked | usagoldmines.com

I built a maxed-out Raspberry 5 mini PC with an SSD for under $200. You can too | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

More Windows 11 patch woes, this time with mouse pointers acting up | usagoldmines.com

These tiny security updates make Google Chrome so much better | usagoldmines.com

This uber mini PC packs a Ryzen 9 and 32GB RAM for just $500 | usagoldmines.com

Most HP printer models have these critical security flaws. Update now! | usagoldmines.com

This slim 10K power bank is only $10 today | usagoldmines.com

Corsair’s new pegboard shelf adds workshop chic to your desk | usagoldmines.com

You can now use AI in Teams to improve poor quality video calls | usagoldmines.com

Update now! This 7-Zip exploit bypasses crucial Windows protections | usagoldmines.com

Need a portable laptop monitor? Get this one for just $60 right now | usagoldmines.com

Bill Gates: ‘Intel lost its way’ | usagoldmines.com

Chrome’s Incognito mode no longer saves copied stuff to clipboard history | usagoldmines.com

OnePlus 13’s Free Double Storage Promo Reaches Final Hours, $500 Cheaper Than Galaxy S25 Ultra Kelle...

Google Photos Adds Digital Watermark for Your Fake, AI-Generated Images Kellen | usagoldmines.com

Threads Now Lets You Share Custom Feeds, Just like Bluesky Khamosh Pathak | usagoldmines.com

How to Clean Your Mac's Keyboard Pranay Parab | usagoldmines.com

Former iPhone 7 Owners Begin Receiving Up to $349 Following Lawsuit Joe Rossignol | usagoldmines.com

Let’s Encrypt halts expiration alerts - but it's for a good reason | usagoldmines.com

2025 Genesis Electrified GV70 review: Wait for the next model year Jonathan M. Gitlin | usagoldmines...

Don’t panic, but an asteroid has a 1.9% chance of hitting Earth in 2032 Stephen Clark | usagoldmines...

US lawmakers push to quickly ban DeepSeek on government devices Ashley Belanger | usagoldmines.com

These tiny security updates make Google Chrome so much better | usagoldmines.com

‘Table for Two’ Encourages You to Pause to Enjoy the Romance of Food Allie Chanthorn Reinmann | usag...

Google Just Launched Gemini 2.0 Flash and Pro for Users and Developers David Nield | usagoldmines.co...

This Ring Doorbell Is Down to Its Lowest Price Ever Pradershika Sharma | usagoldmines.com

All the Gardening Tasks You Should Complete in February Amanda Blum | usagoldmines.com

iOS 18.3.1 Update Coming Soon for iPhones Joe Rossignol | usagoldmines.com

Anker Valentine's Day Sale Offering Big Discounts on Charging Accessories Mitchel Broussard | usagol...

I've seen most of 2025’s flagship robot vacuums and let me tell you, things are about to get weird j...

Invincible season 3 changes Oliver Grayson's shocking and violent coming-of-age moment for the bette...

Veeam backup software has a serious security flaw - here's how to stay safe | usagoldmines.com

Apple's Base 128GB iPhone Storage Tier Needs to Go Tim Hardwick | usagoldmines.com

Leica Announces $329 'LUX Grip' Camera Accessory for iPhone Hartley Charlton | usagoldmines.com

New iPhone Feature for Tracking Lost Baggage Expands to More Airlines Joe Rossignol | usagoldmines.c...

Netflix is getting 2 huge thrillers that I can’t wait for, with Robert De Niro, Gillian Anderson and...

Hurry! It's your last chance to save serious money on the Samsung Galaxy S25 Ultra with these pre-or...

Metal Gear Solid Delta: Snake Eater could launch in August, per new leak dash.wood@futurenet.com (Da...

KitchenAid reveals its color of the year for 2025 – and I want to eat it out of a tub with a spoon ...

Cisco patches critical security issues, so update now | usagoldmines.com

Should you buy Nikon’s new Coolpix P1100? Here are 5 things you need to know about the updated 125x ...

Amazon drops unsubtle hints that Alexa AI is landing soon – 3 things to expect from the new voice as...

Humans not needed: AI-powered autonomous drones fused with RFID technology set to revolutionize ware...

Microsoft authentication system spoofed via phishing attack | usagoldmines.com

ChatGPT Search is now free for everyone, no OpenAI account required – is it time to ditch Google? jo...

Spotify will 'double down' on music in 2025, but does that mean Hi-Fi or AI? | usagoldmines.com

New Nvidia GeForce RTX 5060 Ti and RTX 5060 rumor suggests they could end up being great budget buys...

Leave a Reply