Wednesday, May 28, 2025
HomeAndroidMalicious Android & iOS Apps Downloaded Over 242,000 Times, Stealing Crypto Recovery...

Malicious Android & iOS Apps Downloaded Over 242,000 Times, Stealing Crypto Recovery Keys

Published on

SIEM as a Service

Follow Us on Google News

A sophisticated malware campaign, dubbed SparkCat, has infiltrated Google Play and Apple’s App Store, marking the first known instance of an optical character recognition (OCR)-based cryptocurrency stealer on iOS.

According to cybersecurity firm Kaspersky, the malware has been downloaded over 242,000 times since its emergence in March 2024.

It targets sensitive cryptocurrency wallet recovery phrases stored in images, posing a significant threat to users across Europe, Asia, and beyond.

- Advertisement - Google News
Android & iOS Apps
Negative user feedback about ComeCome

How SparkCat Operates

SparkCat is embedded within malicious software development kits (SDKs) integrated into seemingly legitimate apps.

On Android, it operates via a Java-based SDK named “Spark,” disguised as an analytics module.

Android & iOS Apps
Suspicious SDK being called

For iOS, the malware uses a malicious framework under aliases like “GZIP” or “googleappsdk,” written in Objective-C and obfuscated with HikariLLVM for stealth.

The malware employs Google ML Kit’s OCR technology to scan image galleries for recovery phrases mnemonics critical for accessing cryptocurrency wallets.

These phrases are extracted from screenshots or notes and uploaded to attacker-controlled servers via encrypted channels, including Amazon cloud storage or a Rust-based protocol.

To avoid detection, SparkCat requests gallery access only during specific user actions, such as initiating support chats.

This selective behavior minimizes suspicion while enabling the malware to execute its primary function covertly.

Widespread Impact and Technical Sophistication

The infected apps span various categories, including food delivery services, AI-powered messaging platforms, and crypto-related tools.

Some apps appear legitimate, while others are designed to lure victims.

The campaign’s cross-platform compatibility and use of the Rust programming language a rarity in mobile applications, highlight its technical sophistication.

Kaspersky’s analysis revealed that SparkCat selectively targets users based on keywords in multiple languages, including English, Chinese, Korean, Japanese, and European languages.

To mitigate the risk posed by SparkCat:

  • Uninstall suspicious apps immediately and run antivirus scans.
  • Avoid storing sensitive information like recovery phrases in screenshots or unencrypted formats.
  • Use secure offline storage solutions or hardware wallets for cryptocurrency keys.
  • Regularly update software and avoid downloading apps from unofficial sources.

Google and Apple have been notified about the infected apps; however, some remain available for download.

Users must exercise caution when granting permissions to apps that request access to sensitive data.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data

DocuSign has emerged as a cornerstone for over 1.6 million customers worldwide, including 95%...

Government Calls on Organizations to Adopt SIEM and SOAR Solutions

In a landmark initiative, international cybersecurity agencies have released a comprehensive series of publications...

WordPress TI WooCommerce Wishlist Plugin Flaw Puts Over 100,000 Websites at Risk of Cyberattack

A severe security flaw has been identified in the TI WooCommerce Wishlist plugin, a...

Microsoft Alerts on Void Blizzard Hackers Targeting Telecommunications and IT Sectors

Microsoft Threat Intelligence Center (MSTIC) has issued a critical warning about a cluster of...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data

DocuSign has emerged as a cornerstone for over 1.6 million customers worldwide, including 95%...

Government Calls on Organizations to Adopt SIEM and SOAR Solutions

In a landmark initiative, international cybersecurity agencies have released a comprehensive series of publications...

WordPress TI WooCommerce Wishlist Plugin Flaw Puts Over 100,000 Websites at Risk of Cyberattack

A severe security flaw has been identified in the TI WooCommerce Wishlist plugin, a...