• About
  • FAQ
  • Earn Bitcoin while Surfing the net
  • Buy & Sell Crypto on Paxful
Newsletter
Approx Foundation
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Approx Foundation
No Result
View All Result
Home Bitcoin

Malicious SDKs On Google Play And App Store Steal Crypto Seed Phrases: Kaspersky

Moussa by Moussa
February 5, 2025
in Bitcoin
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Cybersecurity firm Kaspersky Labs has uncovered a sophisticated malware campaign targeting cryptocurrency users through malicious software development kits (SDKs) embedded in mobile apps on Google Play and the Apple App Store.

Related articles

8 Months To Go: Here’s How Bitcoin Could Trend In 2026 – Analyst

8 Months To Go: Here’s How Bitcoin Could Trend In 2026 – Analyst

May 10, 2026
Privacy Narrative Makes Comeback, Ton Jumps, Clarity Comes Into View, and More

Privacy Narrative Makes Comeback, Ton Jumps, Clarity Comes Into View, and More

May 10, 2026

These compromised apps use an optical character recognition (OCR) tool to scan users’ photos for crypto wallet recovery phrases, allowing hackers to drain funds from affected wallets.

In a 4 February 2025 report, Kaspersky analysts Sergey Puzan and Dmitry Kalinin detailed how the malware, known as SparkCat, infiltrates devices and searches for images containing recovery phrases using keyword detection across multiple languages.

EXPLORE: 10 Coins with High Returns: Crypto Forecast 2025

Seed Phrases Allow Attackers to Access Crypto Wallets

Once extracted, these phrases grant attackers complete access to victims’ crypto wallets. “The intruders steal recovery phrases for crypto wallets, which are enough to gain full control over the victim’s wallet for further theft of funds,” the researchers wrote.

They also warned that the malware’s flexibility enables it to steal other sensitive data, such as passwords and private messages captured in screenshots.

On Android, the malware disguises itself as a Java-based analytics module called Spark and receives operational updates via an encrypted configuration file stored on GitLab. It employs Google’s ML Kit OCR to extract text from images stored on infected devices.

If a recovery phrase is detected, the malware transmits it to attackers, who can then import the victim’s crypto wallet onto their own devices without needing a password.

Kaspersky estimates that SparkCat has been downloaded approximately 242,000 times since its emergence in March 2023, primarily targeting users in Europe and Asia.

Since mid-2024, we’ve been tracking a sophisticated Android malware campaign that exploits wedding invitations to deceive users into installing a malicious APK—Tria Stealer.

Once installed, this malware intercepts SMS messages, tracks call logs, and steals data from Gmail and… pic.twitter.com/TQbQjHvmjm

— Kaspersky (@kaspersky) February 3, 2025

The malware has been found across dozens of apps—some appearing legitimate, such as food delivery services, while others are suspiciously designed to attract victims, such as messaging apps with AI features.

The infected apps share common characteristics, including the use of Rust programming language, which is uncommon in mobile applications, cross-platform functionality, and obfuscation techniques that make detection difficult.

EXPLORE: 10 Coins with High Returns: Crypto Forecast 2025

Unidentified Origins

Puzan and Kalinin stated that it remains uncertain whether the affected apps were intentionally embedded with the malware by developers or compromised through a supply chain attack.

“Some apps, such as food delivery services, appear legitimate, while others are clearly built to lure victims,” the researchers noted, adding that several similar-looking AI messaging apps were traced back to the same developer.

Although Kaspersky has not attributed SparkCat to any known hacking group, researchers discovered Chinese-language comments and error messages within the malware’s code, leading them to believe that the developer is fluent in Chinese.

The malware bears similarities to a March 2023 campaign discovered by ESET researchers, but its exact origins remain unknown.

Kaspersky urges users to avoid storing sensitive information, such as crypto wallet recovery phrases, in their photo galleries. Instead, they recommend using password managers and regularly scanning for and removing suspicious applications.

EXPLORE: 15 New & Upcoming Coinbase Listings to Watch in 2025

The post Malicious SDKs On Google Play And App Store Steal Crypto Seed Phrases: Kaspersky appeared first on 99Bitcoins.





Source link

Share76Tweet47

Related Posts

8 Months To Go: Here’s How Bitcoin Could Trend In 2026 – Analyst

8 Months To Go: Here’s How Bitcoin Could Trend In 2026 – Analyst

by Moussa
May 10, 2026
0

Bitcoin is presently trading above $80,000, as market bulls sustain the rebound from early April. However, the flagship cryptocurrency remains...

Privacy Narrative Makes Comeback, Ton Jumps, Clarity Comes Into View, and More

Privacy Narrative Makes Comeback, Ton Jumps, Clarity Comes Into View, and More

by Moussa
May 10, 2026
0

Key TakeawaysSenate Banking neared a CLARITY Act vote, setting up a pivotal U.S. crypto market test in 2026.Pavel Durov drove...

How do Bitcoin mining pools typically handle payout frequency versus thresholds?

Can’t sign using Trezor T derived multisig wallet using Electrum | Invalid script_type

by Moussa
May 10, 2026
0

I created a P2WSH multisig wallet using Electrum 4.0.9 using a single Trezor T, to which I sent a large...

Nvidia Earnings Beat Lifts AI Crypto Tokens and Stocks

Bitcoin News: Where Next for BTC USD After the $80,000 Breakout?

by Moussa
May 10, 2026
0

In Bitcoin news today, the BTC USD price crossed $80,000 late Sunday into May 4, 2026, reaching a high of...

CLARITY Act: Banking Trade Groups Push For Yield Agreement Revision – Details

CLARITY Act: Banking Trade Groups Push For Yield Agreement Revision – Details

by Moussa
May 10, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure US banking trade groups have called for...

Load More

youssufi.com

sephina.com

[vc_row full_width="stretch_row" parallax="content-moving" vc_row_background="" background_repeat="no-repeat" background_position="center center" footer_scheme="dark" css=".vc_custom_1517813231908{padding-top: 60px !important;padding-bottom: 30px !important;background-color: #191818 !important;background-position: center;background-repeat: no-repeat !important;background-size: cover !important;}" footer_widget_title_color="#fcbf46" footer_button_bg="#fcb11e"][vc_column width="1/4"]

We bring you the latest in Crypto News

[/vc_column][vc_column width="1/4"][vc_wp_categories]
[/vc_column][vc_column width="1/4"][vc_wp_tagcloud taxonomy="post_tag"][/vc_column][vc_column width="1/4"]

Newsletter

[vc_raw_html]JTNDcCUzRSUzQ2RpdiUyMGNsYXNzJTNEJTIydG5wJTIwdG5wLXN1YnNjcmlwdGlvbiUyMiUzRSUwQSUzQ2Zvcm0lMjBtZXRob2QlM0QlMjJwb3N0JTIyJTIwYWN0aW9uJTNEJTIyaHR0cHMlM0ElMkYlMkZhcHByb3gub3JnJTJGJTNGbmElM0RzJTIyJTNFJTBBJTBBJTNDaW5wdXQlMjB0eXBlJTNEJTIyaGlkZGVuJTIyJTIwbmFtZSUzRCUyMm5sYW5nJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1maXJzdG5hbWUlMjIlM0UlM0NsYWJlbCUyMGZvciUzRCUyMnRucC0xJTIyJTNFRmlyc3QlMjBuYW1lJTIwb3IlMjBmdWxsJTIwbmFtZSUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1uYW1lJTIyJTIwdHlwZSUzRCUyMnRleHQlMjIlMjBuYW1lJTNEJTIybm4lMjIlMjBpZCUzRCUyMnRucC0xJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0MlMkZkaXYlM0UlMEElM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1lbWFpbCUyMiUzRSUzQ2xhYmVsJTIwZm9yJTNEJTIydG5wLTIlMjIlM0VFbWFpbCUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1lbWFpbCUyMiUyMHR5cGUlM0QlMjJlbWFpbCUyMiUyMG5hbWUlM0QlMjJuZSUyMiUyMGlkJTNEJTIydG5wLTIlMjIlMjB2YWx1ZSUzRCUyMiUyMiUyMHJlcXVpcmVkJTNFJTNDJTJGZGl2JTNFJTBBJTNDZGl2JTIwY2xhc3MlM0QlMjJ0bnAtZmllbGQlMjB0bnAtcHJpdmFjeS1maWVsZCUyMiUzRSUzQ2xhYmVsJTNFJTNDaW5wdXQlMjB0eXBlJTNEJTIyY2hlY2tib3glMjIlMjBuYW1lJTNEJTIybnklMjIlMjByZXF1aXJlZCUyMGNsYXNzJTNEJTIydG5wLXByaXZhY3klMjIlM0UlQzIlQTBCeSUyMGNvbnRpbnVpbmclMkMlMjB5b3UlMjBhY2NlcHQlMjB0aGUlMjBwcml2YWN5JTIwcG9saWN5JTNDJTJGbGFiZWwlM0UlM0MlMkZkaXYlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1idXR0b24lMjIlM0UlM0NpbnB1dCUyMGNsYXNzJTNEJTIydG5wLXN1Ym1pdCUyMiUyMHR5cGUlM0QlMjJzdWJtaXQlMjIlMjB2YWx1ZSUzRCUyMlN1YnNjcmliZSUyMiUyMCUzRSUwQSUzQyUyRmRpdiUzRSUwQSUzQyUyRmZvcm0lM0UlMEElM0MlMkZkaXYlM0UlM0NiciUyRiUzRSUzQyUyRnAlM0U=[/vc_raw_html][/vc_column][/vc_row]
No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2024 APPROX FOUNDATION - The Crypto Currency News