logo

Google Play, Apple App Store apps caught stealing crypto wallets

ID: a33e3456-688c-5445-8758-00fabbdf2087

STIX ID: report--a33e3456-688c-5445-8758-00fabbdf2087

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-02-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky discovered the "SparkCat" campaign: a malicious SDK embedded in Android and iOS apps that uses Google ML Kit OCR (with language-specific models), encrypted GitLab-hosted configuration, and Rust networking modules to find and exfiltrate cryptocurrency wallet recovery phrases to C2 servers; 18 Android and 10 iOS apps were identified (over 242,000 Google Play downloads), some apps remain available in stores, and users are advised to uninstall affected apps, scan devices, and avoid storing recovery phrases as screenshots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.