Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets

Drift loses $285 million in North Korea-related durable Nonce social engineering attack

Amazon imposes ‘fuel surcharge’ on sellers as global energy market turmoil due to Iran war

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets
Identity

New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets

By April 3, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 3, 2026Mobile security/threat intelligence

Cybersecurity researchers have discovered a new version of SparkCat malware on the Apple App Store and Google Play Store. It has been over a year since this Trojan was discovered targeting both mobile operating systems.

The malware has been found hiding inside seemingly innocuous apps like enterprise messengers and food delivery services, silently scanning victims’ photo galleries for recovery phrases for their crypto wallets.

Russian cybersecurity company Kaspersky has announced that it has found two infected apps in the App Store and one in the Google Play Store that primarily target crypto users in Asia.

“However, the iOS variant takes a different approach when scanning for cryptocurrency wallet mnemonic phrases written in English,” the company said. “This could further widen the reach of iOS variants as they can impact users regardless of region.”

The improved version of SparkCat for Android includes several layers of obfuscation compared to previous versions. This includes code virtualization and the use of cross-platform programming languages ​​to avoid analysis efforts. Additionally, the Android version scans for Japanese, Korean, and Chinese keywords, indicating an Asian focus.

SparkCat was first documented by Kaspersky in February 2025, highlighting its ability to leverage optical character recognition (OCR) models to exfiltrate selected images containing wallet recovery phrases from a photo library to an attacker-controlled server.

The latest improvements to this malware indicate that it is an actively evolving threat, not to mention the technical capabilities of the attackers behind this malware. Kaspersky previously attributed the malicious activity to Chinese-speaking operators.

“The updated variant of SparkCat, similar to the first version of the Trojan, requests access to view photos in the user’s smartphone gallery in certain scenarios,” Kaspersky researcher Sergei Puzan told The Hacker News. “Using an optical character recognition module to analyze text in stored images.”

“Once the thieves find a relevant keyword, they send the image to the attackers. Given the similarities between the current and previous samples, we believe the new version of the malware is from the same developer. This campaign once again emphasizes the importance of using security solutions for smartphones to stay protected from a wide range of cyber threats.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDrift loses $285 million in North Korea-related durable Nonce social engineering attack

Related Posts

Drift loses $285 million in North Korea-related durable Nonce social engineering attack

April 3, 2026

Hackers exploit CVE-2025-55182 to compromise 766 Next.js hosts and steal credentials

April 2, 2026

Cisco Patch 9.8 CVSS IMC and SSM flaws allow remote systems to be compromised

April 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets

Drift loses $285 million in North Korea-related durable Nonce social engineering attack

Amazon imposes ‘fuel surcharge’ on sellers as global energy market turmoil due to Iran war

Artemis II is NASA’s last lunar mission without Silicon Valley

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.