Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims
ID: 47aecb94-937a-5177-92b9-b48ed11e06c4
STIX ID: report--47aecb94-937a-5177-92b9-b48ed11e06c4
Feed Name: The Register (Security)
Threat Score
Kaspersky discovered SparkCat, an OCR-enabled stealer embedded in mobile apps (including ComeCome) on iOS and Android that decrypts and runs an OCR plugin to scan screenshots for cryptocurrency wallet recovery phrases and exfiltrates them to a command-and-control server; multiple infected apps were available in official app stores, downloaded over ~242,000 times, and have since been removed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
