Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Security Privacy

First OCR Spyware Breaches Both Apple and Google App Stores To Steal Crypto Wallet Phrases (securelist.com) 14

Kaspersky researchers have discovered malware hiding in both Google Play and Apple's App Store that uses optical character recognition to steal cryptocurrency wallet recovery phrases from users' photo galleries. Dubbed "SparkCat" by security firm ESET, the malware was embedded in several messaging and food delivery apps, with the infected Google Play apps accumulating over 242,000 downloads combined.

This marks the first known instance of such OCR-based spyware making it into Apple's App Store. The malware, active since March 2024, masquerades as an analytics SDK called "Spark" and leverages Google's ML Kit library to scan users' photos for wallet recovery phrases in multiple languages. It requests gallery access under the guise of allowing users to attach images to support chat messages. When granted access, it searches for specific keywords related to crypto wallets and uploads matching images to attacker-controlled servers.

The researchers found both Android and iOS variants using similar techniques, with the iOS version being particularly notable as it circumvented Apple's typically stringent app review process. The malware's creators appear to be Chinese-speaking actors based on code comments and server error messages, though definitive attribution remains unclear.

First OCR Spyware Breaches Both Apple and Google App Stores To Steal Crypto Wallet Phrases

Comments Filter:
  • wtf (Score:3, Insightful)

    by Anonymous Coward on Wednesday February 05, 2025 @03:46PM (#65144879)
    recovery phrases in photo galleries? ummm WTF. People are stupid.
  • by NotEmmanuelGoldstein ( 6423622 ) on Wednesday February 05, 2025 @05:19PM (#65145221)

    ... users' photo galleries.

    This is no different to having the pass-phrase in a text file: Anyone can read it. Worse, Microsoft and Google make a point of copying on-device photos (for your safety, pinky-swear). Microsoft has even been caught installing Recall spyware that makes photos, copies them, then translates them to literal text as a quote or description. With that sort of security hole in modern computers, it's obvious that anything not encrypted is easily stolen. (I side-step the issue that Recall can watch you encrypting stuff, making the activity, insecure.)

    Everyone knows by now, don't attach the password to the device display, don't put it under your keyboard or on your credit card. It demonstrates extreme laziness, to think that a photo is, somehow, more secure. This is simply people refusing to use the software that actually solves this problem: A password manager. Most of them can also encrypt a photo.

  • Seems Kaspersky is always discovering this stuff but USA can't use Kaspersky because it might be ...gulp.... spyware! Maybe someone can point out to Trump that Biden banned it, so he then unbans it.

Wishing without work is like fishing without bait. -- Frank Tyger

Working...