logo

SpyAgent Android malware steals your crypto recovery phrases from images

ID: ab771501-62a1-54a1-b455-cd516784368b

STIX ID: report--ab771501-62a1-54a1-b455-cd516784368b

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-09-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

McAfee researchers uncovered an Android malware campaign called SpyAgent that hijacks sensitive data by scanning screenshots and images with OCR to recover cryptocurrency wallet seed phrases, exfiltrating contacts, incoming SMS (including OTPs), images, and device info to poorly secured C2/admin panels; the campaign has been distributed via at least ~280 sideloaded APKs using SMS and malicious social posts, primarily targeting South Korea with signs of expansion to the UK and potential iOS development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.