Cross-Platform Malware Targets Crypto Wallet Recovery Phrases
- The “SparkCat” malware campaign targets cryptocurrency wallet recovery phrases through malicious mobile apps.
- First observed in March 2023, the malware uses a software development kit (SDK) to scan image galleries for sensitive data.
- The campaign affects Android and iOS devices via apps on both official and unofficial marketplaces.
- Affected apps, including one called “ComeCome,” have been installed over 242,000 times.
- Malware employs Google’s ML Kit library for optical character recognition (OCR) to detect mnemonics in images.
The SparkCat campaign has impacted over 242,000 app installations by embedding an SDK that scans image galleries for crypto wallet recovery phrases using OCR technology.
Source (2.6)https://decrypt.co/304595/crypto-stealing-malware-google-apple-apps?rand=52368