Loading IndicatorLoading Indicator

SparkKitty Malware Targeting Crypto Users Found on Apple App Store, Google Play

Source
Bloomingbit Newsroom

Summary

  • A new malware strain targeting cryptocurrency users, SparkKitty, has been found on the App Store and Google Play.
  • Check Point said SparkKitty uses OCR to extract cryptocurrency wallet recovery phrases (seed phrases) from images and send them to hacker-controlled servers.
  • Check Point said users who store wallet recovery phrases as screenshots or photos face the greatest risk.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

A new malware strain targeting cryptocurrency users, dubbed SparkKitty, has been found on Apple’s App Store and Google Play.

Crypto news outlet The Block reported on July 27 that cybersecurity firm Check Point said in a report released that day that SparkKitty had been distributed through multiple channels, including the App Store, Google Play and third-party Android app markets. The malware uses optical character recognition, or OCR, to scan images stored on infected devices and extract cryptocurrency wallet recovery phrases, also known as seed phrases.

Check Point said SparkKitty appears to be an evolved version of SparkCat, an information-stealing malware strain identified previously. SparkCat also used OCR to collect data from screenshots.

The malware was hidden in applications disguised as crypto services, messaging platforms and entertainment apps. After installation, it requests access to the photo library. It then continuously scans both existing images on the device and newly added ones. Extracted wallet recovery phrases, passwords and QR code data are sent to hacker-controlled servers along with basic device information.

On iOS, the malware was embedded in a crypto-related app listed on the App Store under the name BiCoin. On Android, SparkKitty was found in an app called SOEX that posed as a messaging and crypto trading platform. The app was downloaded more than 10,000 times before Google Play removed it.

Check Point said a recovery phrase alone is enough to give attackers full access to a wallet. Users who store wallet recovery phrases as screenshots or photos face the greatest risk.

#Malware
#Crypto Hack
Bloomingbit Newsroom

Bloomingbit Newsroom

news@bloomingbit.ioFor news reports, news@bloomingbit.io

What do you think about this news?








PiCK News






Hashtag News