logo

New Android SpyAgent Campaign Steals Crypto Credentials via Image Recognition

ID: 29747455-aaa3-5469-b6d6-c40b08926979

STIX ID: report--29747455-aaa3-5469-b6d6-c40b08926979

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2024-09-05

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research uncovered SpyAgent, an Android malware campaign that masquerades as legitimate apps to phish users into installing malicious APKs; once installed it harvests contacts, SMS, device info and photos (using OCR to extract mnemonic wallet phrases), exfiltrates data to poorly secured C2 servers (resulting in leaked victim images), and has evolved to use WebSocket communications and stronger obfuscation—active in Korea since January 2024 with signs of expansion to the UK and provided SHA256 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.