Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Kaspersky: SparkCat malware is a nightmare for crypto owners

According to Kaspersky, this app is designed to seize access to users’ cryptocurrency by capturing screenshots containing recovery phrases, also referred to as seed phrases

byKerem Gülen
February 7, 2025
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Kaspersky researchers have identified a malware campaign, dubbed SparkCat, distributing malicious applications on both Android and iOS platforms since March 2024. This malware employs optical character recognition (OCR) to scan photo libraries for cryptocurrency wallet recovery phrases.

“Kaspersky Threat Research expertise center has discovered a new data-stealing Trojan, SparkCat, active in AppStore and Google Play since at least March 2024. This is the first known instance of optical recognition-based malware appearing in AppStore. SparkCat uses machine learning to scan image galleries and steal screenshots containing cryptocurrency wallet recovery phrases. It can also find and extract other sensitive data in images, such as passwords.”

-Kaspersky

Kaspersky identifies SparkCat malware targeting crypto wallets on iOS and Android

The investigation, conducted by Dmitry Kalinin and Sergey Puzan, noted that while some of the affected apps, like food delivery services, seem legitimate, others appear to deliberately deceive users. On February 6, Kaspersky confirmed that affected applications had been removed from the App Store, with Apple reporting the deletion of 11 apps that shared code with an additional 89 apps previously rejected or removed due to security concerns.

The malware was primarily found in an iOS app named ComeCome, which also appears on Google Play. According to Kaspersky, this app is designed to seize access to users’ cryptocurrency by capturing screenshots containing recovery phrases, also referred to as seed phrases. The malware operates by using a malicious software development kit (SDK) that decrypts an OCR plugin, which facilitates the scanning of mobile device screenshots.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

SparkCat malware is a nightmare for crypto owners
Image: Kaspersky

Kaspersky highlighted that infected Google Play applications have been downloaded over 242,000 times. This incident marks the first discovery of an app infected with OCR spyware in Apple’s App Store, challenging the notion of the platform’s infallibility against malware threats.


Flexible-Ferret malware targets Mac users by doding XProtect measures


The malware not only targets crypto wallet recovery phrases but is also flexible enough to extract other sensitive information from the gallery, such as messages or passwords captured in screenshots. The researchers emphasized that the malware’s requests for permissions may appear benign or necessary, allowing it to evade detection.

The SparkCat malware campaign is estimated to target Android and iOS users mainly in Europe and Asia. Kaspersky noted that the exact method of infection is still under investigation, as they cannot confirm whether SparkCat was introduced through a supply chain attack or malicious developer actions.

SparkCat malware is a nightmare for crypto owners
Image: Kaspersky

In related findings, Spark encompasses an obfuscated module identified as Spark, primarily written in Java, which communicates with a remote command-and-control (C2) server via a Rust-based protocol. Upon connecting to the C2 server, the malware utilizes Google’s ML Kit library’s TextRecognizer interface to extract text from images.

Additional analysis revealed that the malware’s deceitful nature allows it to mislead users into granting access to their photo libraries after they capture screenshots of recovery phrases. Kaspersky’s detailed report stated that “the permissions that it requests may look like they are needed for its core functionality or appear harmless at first glance.”


Featured image credit: Kerem Gülen/Ideogram

Tags: CybersecurityFeaturedMalware

Related Posts

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

June 3, 2026
Crypto investors are watching one date closely in 2026

Crypto investors are watching one date closely in 2026

June 3, 2026
How Telegram Creators test post visibility before running growth campaigns

How Telegram Creators test post visibility before running growth campaigns

June 3, 2026
Does your AI clock in without you?

Does your AI clock in without you?

June 3, 2026
Why secure software delivery depends on better release management

Why secure software delivery depends on better release management

June 3, 2026
Sony reveals God of War: Laufey for PS5

Sony reveals God of War: Laufey for PS5

June 3, 2026

LATEST NEWS

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

Crypto investors are watching one date closely in 2026

How Telegram Creators test post visibility before running growth campaigns

Does your AI clock in without you?

Why secure software delivery depends on better release management

Sony reveals God of War: Laufey for PS5

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Veed.io

Paper Pilot

IsOn24

Magnific

DADABOTS

Rosebud AI

Prome

Pageon AI

Vyond

Centauri AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.