Crypto Wallets
Malicious Software Scans for Crypto Wallet Recovery Phrases
Wednesday. February 5 at 9:00 AM
1 min. readCybersecurity firm Kaspersky Labs reported that malicious software development kits on Google's Play Store and Apple's App Store are scanning users' images to locate crypto wallet recovery phrases for fund theft. The malware, SparkCat, searches for specific keywords in various languages through optical character recognition to steal recovery phrases and other personal data from the gallery. Kaspersky advises against storing sensitive information in screenshots and recommends using a password manager. The malware, downloaded approximately 242,000 times, targets Android and iOS users in Europe and Asia. It is present in numerous apps across both app stores, utilizing the Rust language, cross-platform capability, and obfuscation for evasion. The malware's origin remains unclear, with similarities to a 2023 campaign discovered by ESET researchers. Google and Apple have not commented on the issue.