Take my money: OCR crypto stealers in Google Play and App Store
ID: 09c47182-0c6b-51fc-91de-5406f0403a60
STIX ID: report--09c47182-0c6b-51fc-91de-5406f0403a60
Feed Name: Securelist by Kaspersky
Kaspersky researchers uncovered ‘SparkCat’, a cross-platform mobile stealer embedded in multiple Android and iOS apps (some present in Google Play and the App Store) that uses Google ML Kit OCR and a Rust-based native module to scan gallery images for cryptocurrency wallet recovery phrases and exfiltrate matching images to attacker-controlled C2 infrastructure; the report details technical analysis, C2 protocols and encryption, lists IOCs (app bundle IDs, APKs, hashes, domains, GitLab config), and provides removal and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
