Crypto-stealing apps found in Apple App Store for the first time
ID: b66047f5-efc7-5e4c-82f4-6be9873534c3
STIX ID: report--b66047f5-efc7-5e4c-82f4-6be9873534c3
Feed Name: Bleeping Computer
Kaspersky reported a campaign named "SparkCat" where malicious SDKs embedded in Android and iOS apps abuse Google ML Kit OCR and language-specific models to locate and exfiltrate cryptocurrency wallet recovery phrases. The SDKs (named Spark, Gzip, googleappsdk, stat and others) retrieve encrypted operational configs from GitLab and communicate with C2 servers; Kaspersky found 18 Android and 10 iOS infected apps (over 242,000 Google Play downloads) and noted this is the first known stealer discovered in the App Store, prompting removals and developer bans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
