SparkCat Crypto Stealer Malware Infected Multiple Apps on Play Store, App Store

This is the first time that apps with cryptocurrency stealing malware have been detected on Apple's App Store.

Advertisement
Written by David Delima | Updated: 6 February 2025 14:47 IST
Highlights
  • A crypto stealer malware infected 28 apps for iOS and Android smartphones
  • The apps would detect wallet recovery phrases using OCR technology
  • The SparkCat malware was detected on both the App Store and Play Store

Recovery phrases can be used to gain access to crypto wallets

Photo Credit: Pexels/ Alesia Kozik

Several apps on the App Store and Google Play store were found to be infected with a crypto stealer malware by security researchers at Kaspersky. These applications reportedly included a malicious software development kit (SDK) that was designed to use optical character recognition (OCR) to steal "crypto wallet recovery phrases" from screenshots stored on a user's smartphone. It's also worth noting that this is the first time that apps with cryptocurrency stealing malware have been detected on Apple's App Store.

SparkCat Infected Apps Detected Crypto Wallet Recovery Phrases Stored Using Screenshots

In a detailed technical report published on Thursday, the researchers said that at least 18 Android applications were infected with the malicious SparkCat SDK, while the malicious framework was found in 10 iOS apps on the App Store. The cumulative download count on Android smartphones was over 2.42 lakh, according to the researchers.

Advertisement

Two of the infected apps on the Play Store (left) and App Store
Photo Credit: Kaspersky

Advertisement

 

Some of the infected applications appeared to be legitimate, while others (specifically messaging apps equipped with AI features) were published in order to tempt users to download the compromised application, as per the report. Meanwhile, Kaspersky said that some of the infected Android apps were still available to download via the Play Store at the time of publishing its report.

Advertisement

However, the researchers say that they cannot confirm whether the apps were infected by the developers on purpose, or whether they were impacted by a supply chain attack. Apple and Google have yet to publicly comment on the detection of these apps on their respective app stores.

Once installed on a user's device, these malicious apps would use a OCR technology to detect and extract text from images stored on the handset. Once the app detects a recovery phrase for a cryptocurrency wallet, it would upload the picture to an Amazon cloud server and send a message to the attacker's server to notify them when a recovery phrase is detected.

Advertisement

While Google and Apple have removed most of the apps detected by Kaspersky, users who have downloaded them will need to manually uninstall these applications. Meanwhile, it's worth storing recovery phrases for crypto wallets and accounts in a password manager, or an application that stores encrypted notes. This is considerably safer than keeping screenshots that are easily accessible to apps that have been granted the 'storage' or 'camera roll' permission.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  2. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  3. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  4. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  5. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  6. Vivo Y31s Launched in Malaysia With These Features
  7. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  8. Infinix Smart 20 Launched in India With a 7.7mm Slim Body, Ultra Link Support
  9. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  10. Samsung Galaxy Watch Ultra 2, Watch 9 Visit China's 3C Ahead of Launch
  1. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  2. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  3. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  4. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  5. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  6. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
  7. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  8. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  9. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  10. Asus Dawn 7 Pro Series Launched With Up to 16-Inch 144Hz Display, AMD Ryzen AI 7 445 Chip: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.