HomeSecuritySparkCat malware uses OCR to invade crypto wallets

SparkCat malware uses OCR to infiltrate crypto wallets

A new malware campaign, known as SparkCat, has exploited a series of fake apps uploaded to Apple and Google’s official app stores to steal users’ passphrases associated with crypto wallets, thereby compromising the security of their funds.

See also: Infostealer malware impersonates DeepSeek tools on PyPI

SparkCat malware

The attacks leverage optical character recognition (OCR) technology to analyze specific images containing wallet recovery phrases. These images are pulled from photo libraries and sent to a command and control (C2) server , Kaspersky researchers Dmitry Kalinin and Sergey Puzan said in a technical report.

The name refers to an embedded software development kit (SDK) that leverages a Java component known as Spark, which operates disguised as an analytics engine. At this time, it remains unclear whether the infection resulted from a supply chain or was intentionally introduced by the developers themselves.

While this is not the first time that Android malware with OCR capabilities has been detected, it is one of the few cases where such software has also been detected on Apple's App Store. Meanwhile, the infected apps on Google Play are estimated to have been downloaded more than 242,000 times, underscoring the severity of the issue.

See also: Fake Reddit and WeTransfer pages distribute Lumma Stealer malware

The campaign is estimated to have been active since March 2024, with the apps distributed through both official and unofficial app stores. The apps are disguised as artificial intelligence (AI), food delivery, and Web3 apps, although some of them appear to offer legitimate functionality.

SparkCat malware uses OCR to infiltrate crypto wallets

Similarly, the iOS version of the SparkCat malware relies on ML Kit library for OCR to steal images containing mnemonic phrases. A notable aspect of the malware is its use of a Rust-based communication mechanism for C2, something rarely seen in mobile.

Further analysis of the keywords used and the regions in which these applications were distributed shows that the campaign is primarily targeting users in Europe and Asia. It is believed that the malicious activity is the work of a hacking group that speaks fluent Chinese.

See also: Phishing: PNGPlug Loader distributes ValleyRAT malware

A malware campaign targeting cryptocurrency users is garnering significant attention due to its sophisticated tactics and widespread impact. These campaigns often exploit vulnerabilities in software or rely on phishing techniques to infect systems with malware. Once deployed, the malware is capable of stealing private keys, wallets, or even credentials, leading to the loss of valuable digital assets. To combat such threats, users are advised to enable two-factor authentication, regularly update their software, and remain vigilant against suspicious links or emails.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS