Malware on Google Play, Apple App Store stole your photos—and crypto
ID: 78b85cdd-10dc-543f-a5d7-12e5b11f304a
STIX ID: report--78b85cdd-10dc-543f-a5d7-12e5b11f304a
Feed Name: Bleeping Computer
Kaspersky and BleepingComputer reported a cross‑platform mobile malware campaign (SparkKitty) active since at least February 2024 that infiltrated official and unofficial app stores; the malicious apps request gallery/storage access, exfiltrate images (sometimes using OCR/Google ML Kit to detect text) and aim to steal cryptocurrency wallet recovery phrases and other sensitive photos—apps identified (SOEX, 币coin) have been removed and users are advised to deny gallery access, avoid storing seed phrases as images, and scrutinize apps and provisioning profiles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
