Crypto-Stealing Apps Found in Apple App Store – What You Need to Do Now
Crypto-Stealing Apps Found in Apple App Store – What You Need to Do Now
Malicious Apps Target Crypto Wallets
Security researchers at Kaspersky have uncovered a dangerous new malware targeting cryptocurrency users through apps in the Apple App Store and Google Play Store. These malicious apps contain a software development kit (SDK) named SparkCat, designed to steal cryptocurrency wallet recovery phrases using optical character recognition (OCR) technology.
First Time on Apple App Store – A Growing Threat
Previously, SparkCat was only detected on Android devices, where over 242,000 downloads were reported. However, this marks the first known instance of crypto-stealing malware infiltrating the Apple App Store.
“The iOS malware module was similarly designed and also used the Google ML Kit library for OCR.” – Kaspersky Lab
How Does SparkCat Steal Your Crypto?
Hackers use OCR technology to extract recovery phrases from screenshots stored in a phone’s gallery. Once the malware identifies sensitive data, it sends it to remote servers controlled by hackers, allowing them to gain access to victims’ cryptocurrency wallets.
- Android malware module: Uses OCR via Google ML Kit library to scan text in images
- iOS malware module: Functions similarly, extracting crypto-related text
- Command & Control (C2) communications: Hackers receive and extract critical data remotely
What to Do If You Installed These Apps
If you suspect that you’ve installed a malicious crypto-stealing app, take immediate action to protect your funds and personal data.
Step 1: Uninstall the App Immediately
- Check for suspicious apps: If you recently installed a new crypto-related app, remove it right away.
- Use trusted sources: Only download apps from verified developers with high ratings.
Step 2: Secure Your Cryptocurrency Wallet
- Transfer your funds: If you store cryptocurrency in a hot wallet, move your assets to a cold wallet (hardware wallet).
- Change recovery phrases: If you suspect a leak, generate a new recovery phrase and secure it offline.
- Enable two-factor authentication (2FA): Strengthen security by using an authentication app like Google Authenticator.
Step 3: Avoid Storing Recovery Phrases on Your Device
- Never take screenshots: Screenshots of wallet recovery phrases stored in your gallery can be easily stolen.
- Use secure password managers: Store your crypto keys in a trusted password manager instead.
- Write it down manually: Keep a physical copy of your recovery phrase in a secure location.
Step 4: Install Reliable Security Software
- Use a trusted antivirus: Security solutions like Kaspersky, Norton, or Bitdefender can help detect threats.
- Regularly scan your phone: Perform malware scans to identify suspicious apps or activities.
Future Risks – Will Apple & Google Prevent More Attacks?
While Google and Apple have strict security measures, hackers are finding new ways to infiltrate app stores. Security experts warn that malware attacks on cryptocurrency users will continue to rise, making it crucial to stay vigilant and proactive.
How Can You Stay Safe?
- Verify app permissions: If an app asks for unnecessary permissions, be cautious.
- Keep your OS updated: Regular software updates help fix security vulnerabilities.
- Follow crypto security best practices: Always double-check sources before storing sensitive information.
Final Thoughts – Protect Your Crypto Now!
With crypto adoption growing, hackers are targeting unsuspecting users through deceptive apps. The discovery of SparkCat malware in the Apple App Store is a wake-up call for crypto holders.
Take action now: Uninstall malicious apps, secure your funds, and follow best security practices to stay safe.
Disclaimer: The above press release has been provided by a third party. We do not verify or endorse the content and will not be responsible for any inaccuracies, claims, or damages arising from the same.
