SparkKitty Malware Targets Crypto Users on Apple's App Store and Google Play
A new malware strain, SparkKitty, has been discovered on Apple's App Store and Google Play. This information-stealing malware uses Optical Character Recognition (OCR) technology to extract wallet recovery phrases from images stored on infected devices.
Check Point reported that SparkKitty was distributed through multiple channels, including the App Store, Google Play, and third-party Android app markets. The malware was disguised as crypto services, messaging platforms, and entertainment apps, and requests access to a user's photo library after installation.
On iOS, SparkKitty was embedded in an app called Bcoin listed on the App Store, while on Android, it was found in an app called SOEX that posed as a messaging and crypto trading platform. It was downloaded over 10,000 times before being removed from Google Play.