SpyAgent Android malware steals your crypto recovery phrases from images
ID: ab771501-62a1-54a1-b455-cd516784368b
STIX ID: report--ab771501-62a1-54a1-b455-cd516784368b
Feed Name: Bleeping Computer
McAfee researchers uncovered an Android malware campaign called SpyAgent that hijacks sensitive data by scanning screenshots and images with OCR to recover cryptocurrency wallet seed phrases, exfiltrating contacts, incoming SMS (including OTPs), images, and device info to poorly secured C2/admin panels; the campaign has been distributed via at least ~280 sideloaded APKs using SMS and malicious social posts, primarily targeting South Korea with signs of expansion to the UK and potential iOS development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
