{"id":233446,"date":"2025-02-06T21:11:15","date_gmt":"2025-02-06T21:11:15","guid":{"rendered":"https:\/\/news.talkwithrattan.com\/index.php\/2025\/02\/06\/this-crypto-malware-infected-several-apps-on-the-play-store-app-store\/"},"modified":"2025-02-06T21:11:15","modified_gmt":"2025-02-06T21:11:15","slug":"this-crypto-malware-infected-several-apps-on-the-play-store-app-store","status":"publish","type":"post","link":"https:\/\/news.talkwithrattan.com\/index.php\/2025\/02\/06\/this-crypto-malware-infected-several-apps-on-the-play-store-app-store\/","title":{"rendered":"This Crypto Malware Infected Several Apps on the Play Store, App Store"},"content":{"rendered":"<div style=\"text-align:center\"><img decoding=\"async\" src=\"https:\/\/i3.wp.com\/i.gadgets360cdn.com\/resized\/sparkcat_malware_kaspersky_1738833239603-1200x338.jpeg?ssl=1\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"This Crypto Malware Infected Several Apps on the Play Store, App Store\" title=\"This Crypto Malware Infected Several Apps on the Play Store, App Store\" \/><\/div><p> <br \/>\n<\/p>\n<div id=\"center_content_div\">\n<div class=\"content_text row description\">\n<p>Several apps on the <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/tags\/app-store\">App Store<\/a> and <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/tags\/google-play-store\">Google Play store<\/a> were found to be infected with a crypto stealer malware by security researchers at Kaspersky. These applications reportedly included a malicious software development kit (SDK) that was designed to use optical character recognition (OCR) to steal &#8220;crypto wallet recovery phrases&#8221; from screenshots stored on a user&#8217;s smartphone. It&#8217;s also worth noting that this is the first time that apps with cryptocurrency stealing malware have been detected on Apple&#8217;s App Store.<\/p>\n<h2>SparkCat Infected Apps Detected Crypto Wallet Recovery Phrases Stored Using Screenshots<\/h2>\n<p>In a detailed <a class=\"sp_lnk2\" href=\"https:\/\/securelist.com\/sparkcat-stealer-in-app-store-and-google-play\/115385\/\" rel=\"nofollow noopener\" target=\"_blank\">technical report<\/a> published on Thursday, the researchers said that at least 18 Android applications were infected with the malicious SparkCat SDK, while the malicious framework was found in 10 iOS apps on the App Store. The cumulative download count on <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/android\">Android<\/a> smartphones was over 2.42 lakh, according to the researchers.<\/p>\n<p><span class=\"mt-enclosure mt-enclosure-image\" style=\"display: inline;\"><a href=\"https:\/\/i.gadgets360cdn.com\/large\/sparkcat_malware_kaspersky_1738833239603.jpg\" onclick=\"window.open(https:\/\/i.gadgets360cdn.com\/large\/sparkcat_malware_kaspersky_1738833239603.jpg,'popup','width=1280,height=960,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false;\" target=\"_blank\" rel=\"noopener\"><\/a><\/span><\/p>\n<p class=\"ins_instory_dv_caption\">Two of the infected apps on the Play Store (left) and App Store<br \/><span class=\"ins_instory_span_credit\">Photo Credit: Kaspersky<\/span><\/p>\n<p>\u00a0<\/p>\n<p>Some of the infected applications appeared to be legitimate, while others (specifically messaging apps equipped with <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/artificial-intelligence\">AI<\/a> features) were published in order to tempt users to download the compromised application, as per the report. Meanwhile, Kaspersky said that some of the infected Android apps were still available to download via the Play Store at the time of publishing its report.<\/p>\n<p>However, the researchers say that they cannot confirm whether the apps were infected by the developers on purpose, or whether they were impacted by a supply chain attack. <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/apple\">Apple<\/a> and <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/google\">Google<\/a> have yet to publicly comment on the detection of these apps on their respective app stores.<\/p>\n<p>Once installed on a user&#8217;s device, these malicious apps would use a <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/tags\/ocr\">OCR<\/a> technology to detect and extract text from images stored on the handset. Once the app detects a recovery phrase for a cryptocurrency wallet, it would upload the picture to an <a class=\"sp_lnk2\" href=\"https:\/\/www.gadgets360.com\/tags\/amazon\">Amazon<\/a> cloud server and send a message to the attacker&#8217;s server to notify them when a recovery phrase is detected.<\/p>\n<p>While Google and Apple have removed most of the apps detected by Kaspersky, users who have downloaded them will need to manually uninstall these applications. Meanwhile, it&#8217;s worth storing recovery phrases for crypto wallets and accounts in a password manager, or an application that stores encrypted notes. This is considerably safer than keeping screenshots that are easily accessible to apps that have been granted the &#8216;storage&#8217; or &#8216;camera roll&#8217; permission.<\/p>\n<\/div>\n<p class=\"downloadtxt margin_b20\">\n                For the latest <a href=\"https:\/\/www.gadgets360.com\/news\">tech news<\/a> and <a href=\"https:\/\/www.gadgets360.com\/reviews\">reviews<\/a>, follow Gadgets 360 on <a href=\"https:\/\/twitter.com\/gadgets360\" target=\"_blank\" rel=\"nofollow noopener\">X<\/a>, <a href=\"https:\/\/facebook.com\/gadgets360\" target=\"_blank\" rel=\"nofollow noopener\">Facebook<\/a>, <a href=\"https:\/\/whatsapp.com\/channel\/0029VaB3o5hHltY9SJbXg335\" target=\"_blank\" rel=\"nofollow noopener\">WhatsApp<\/a>, <a href=\"https:\/\/www.threads.net\/@gadgets.360\" target=\"_blank\" rel=\"nofollow noopener\">Threads<\/a> and <a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMILm3AowtoHPAQ?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"nofollow noopener\">Google News<\/a>. For the latest videos on gadgets and tech, subscribe to our <a href=\"https:\/\/www.youtube.com\/channel\/UCx5e1u7BX0aKwEj3sdYXdXg?sub_confirmation=1\" target=\"_blank\" rel=\"nofollow noopener\">YouTube channel<\/a>. If you want to know everything about top influencers, follow our in-house <a href=\"https:\/\/www.whosthat360.com\/\" target=\"_blank\" rel=\"noopener\">Who&#8217;sThat360<\/a> on <a href=\"https:\/\/www.instagram.com\/whosthat360\/\" target=\"_blank\" rel=\"nofollow noopener\">Instagram<\/a> and <a href=\"https:\/\/www.youtube.com\/@WhosThat360\" target=\"_blank\" rel=\"nofollow noopener\">YouTube<\/a>.            <\/p>\n<div class=\"story_nextprv\">\n<div class=\"left_story\">\n            <a href=\"https:\/\/www.gadgets360.com\/mobiles\/news\/asus-zenfone-12-ultra-launch-price-specifications-features-7646468\"><br \/>\n                <i class=\"sprite\"\/><\/p>\n<div class=\"story_image\">\n                    <img decoding=\"async\" class=\"lazy\" src=\"https:\/\/i.gadgets360cdn.com\/large\/asus_zenfone_12_ultra_small_1738824803275.jpg?downsize=90:68&amp;output-quality=70\" alt=\"\" width=\"90\" height=\"68\" loading=\"lazy\"\/>\n                <\/div>\n<p>                <span>Asus Zenfone 12 Ultra With Snapdragon 8 Elite Chip, 5,500mAh Battery Launched: Price, Specifications<\/span><br \/>\n            <\/a>\n        <\/div>\n<\/div><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/www.gadgets360.com\/apps\/news\/sparkcat-crypto-stealer-malware-ocr-google-play-app-store-7647429#rss-gadgets-news\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Several apps on the App Store and Google Play store were found to be infected with a crypto stealer malware by security researchers at Kaspersky. These applications reportedly included a malicious software development kit (SDK) that was designed to use optical character recognition (OCR) to steal &#8220;crypto wallet recovery phrases&#8221; from screenshots stored on a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":233447,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","fifu_image_url":"https:\/\/i.gadgets360cdn.com\/resized\/sparkcat_malware_kaspersky_1738833239603-1200x338.jpeg","fifu_image_alt":"","footnotes":""},"categories":[607],"tags":[182289,1330,6130,4251,182288,182291,22772,182290,30610,1557,182287,9354],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/233446"}],"collection":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/comments?post=233446"}],"version-history":[{"count":1,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/233446\/revisions"}],"predecessor-version":[{"id":233448,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/233446\/revisions\/233448"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/media\/233447"}],"wp:attachment":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/media?parent=233446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/categories?post=233446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/tags?post=233446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}