logo

Take my money: OCR crypto stealers in Google Play and App Store

ID: 09c47182-0c6b-51fc-91de-5406f0403a60

STIX ID: report--09c47182-0c6b-51fc-91de-5406f0403a60

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2025-02-05

Date Updated: 2026-04-29

Author: Dmitry Kalinin, Sergey Puzan

...
...

Kaspersky researchers uncovered ‘SparkCat’, a cross-platform mobile stealer embedded in multiple Android and iOS apps (some present in Google Play and the App Store) that uses Google ML Kit OCR and a Rust-based native module to scan gallery images for cryptocurrency wallet recovery phrases and exfiltrate matching images to attacker-controlled C2 infrastructure; the report details technical analysis, C2 protocols and encryption, lists IOCs (app bundle IDs, APKs, hashes, domains, GitLab config), and provides removal and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.