Apps on the Google Play Store and Apple App Store contain a software development kit (SDK) that steals crypto wallet recovery phrases via optical character recognition (OCR) stealers.

The malicious campaign is called “SparkCat” after the name (“Spark”) of one of the malicious SDK components in the infected apps. Developers are likely unaware that their apps are part of the attack.
According to Kaspersky, on Google Play, the infected apps had more than 242,000 downloads.
See also: US: North Korean hackers stole $659 million worth of crypto in 2024
“ We found Android and iOS apps that had a malicious SDK/framework embedded for stealing crypto wallet recovery phrases. Some were available on Google Play and the App Store , ” Kaspersky explains .
Spark SDK steals victims' crypto
The malicious SDK found in infected Android apps uses a Java component called “Spark,” which is presented as an analytics module. It uses an encrypted configuration file stored on GitLab. This provides commands and functional updates.
On the iOS platform, the framework has different names like “Gzip“, “googleappsdk“, or “stat“. It also uses a Rust-based networking module called “im_net_sys” to handle communication with command and control (C2) servers.
The module uses Google ML Kit OCR to extract text from images on the device. In doing so, it attempts to identify recovery phrases that can be used to load crypto wallets onto attackers' devices.
See also: Crypto-romance scams are on the rise – how to avoid them
“The malicious component loads different OCR models depending on the system language. It can distinguish Latin, Korean, Chinese and Japanese characters in images,” Kaspersky explains.
“The SDK then uploads information about the device to the command server and receives an object that configures the subsequent operation of the malware,” the researchers added.
The malware searches for images containing secrets using specific keywords in different languages.
Infected apps on App Store and Google Play
According to Kaspersky, there are eighteen infected Android apps and 10 iOS apps. One of these apps is Android ChatAi, which was installed more than 50,000 times. This app is no longer available on Google Play.

A full list of affected applications can be found at the end of Kaspersky's report.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Those who have downloaded any of the malicious apps are urged to uninstall them immediately and use an antivirus tool. A factory reset should also be considered.
See also: Malicious VSCode extensions target crypto developers and investors
With the growing popularity of crypto, it is becoming increasingly important for both users and app developers to be aware of risks security and take the necessary precautions. App stores should also implement stricter vetting procedures to prevent the distribution of such malicious SDKs in order to better protect their users. This incident highlights the need for continuous monitoring and regular updates to address any vulnerabilities that cybercriminals may exploit.
Additionally, to reduce the possibility of infection via optical character recognition (OCR) stealers, it is a good idea to avoid saving crypto wallet recovery phrases in screenshots.
Source: www.bleepingcomputer.com
