Cybersecurity firm Kaspersky has warned of malware-infected apps on Google Play and the App Store targeting crypto wallet users and stealing recovery phrases.
Detection of Malicious Apps
Kaspersky reported finding malware-infested apps masquerading as legitimate ones, such as WeTink, AnyGPT, and ComeCome. These apps contained the SparkCat virus, which surreptitiously steals user data.
Technology and Impact
The fraudulent apps used Optical Character Recognition (OCR) technology to scan users’ photo libraries for sensitive data. This information was sent to attackers' remote servers, potentially leading to financial losses. SparkCat is built on a Rust-based protocol and requests photo access via disguised app features, making detection challenging.
Security Measures and Next Steps
Kaspersky experts advise users to avoid saving recovery phrases as screenshots and to transfer assets to new wallets if compromise is detected. The company continues to monitor and report on crypto space threats.
The emergence of malware on platforms with high-security standards, such as iOS, raises industry concerns. Apple is expected to release security updates to protect its users soon.