logo

Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims

ID: 47aecb94-937a-5177-92b9-b48ed11e06c4

STIX ID: report--47aecb94-937a-5177-92b9-b48ed11e06c4

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-02-07

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Kaspersky discovered SparkCat, an OCR-enabled stealer embedded in mobile apps (including ComeCome) on iOS and Android that decrypts and runs an OCR plugin to scan screenshots for cryptocurrency wallet recovery phrases and exfiltrates them to a command-and-control server; multiple infected apps were available in official app stores, downloaded over ~242,000 times, and have since been removed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.