This page was machine-translated and may differ from the original. View original
Kaspersky Confirms 'SparkCat' Variant Bypassing App Store and Google Play
Scan the photo gallery disguised as a legitimate app
Search for cryptocurrency recovery phrases with OCR
Kaspersky announced on April 27 that its threat research team identified two infected apps on the App Store and one on Google Play. SparkCat was rediscovered in a variant form about a year after being removed from both major app platforms.
This variant was distributed disguised as legitimate applications, such as enterprise messengers and food delivery apps. If a user grants permission to access photos, it checks images in the device's gallery and analyzes the characters contained within them using an Optical Character Recognition (OCR) module. The structure is designed to transmit the corresponding image to the attacker if relevant keywords are detected.
The search targets varied by platform. The Android variant was designed to find screenshots containing Japanese, Korean, and Chinese keywords. Based on this, Kaspersky analyzed that this campaign was primarily aimed at cryptocurrency users in Asia. The iOS variant searches for wallet recovery phrases written in English, potentially affecting users without regional restrictions.
Technically, methods that make detection more difficult than before have been applied. The latest Android variants include multi-layered obfuscation structures, code virtualization, and the use of cross-platform programming languages. Kaspersky explained that these techniques are uncommon in mobile malware.
Kaspersky reported the identified malicious app to Google and Apple, and the app has now been removed from the official stores. However, distribution through third-party channels was also confirmed, and some web pages were found to be disguised by displaying a screen similar to the App Store to iPhone users.
Security experts advise against saving images containing cryptocurrency wallet recovery phrases or personal authentication information on smartphones. When installing apps, check the source and the scope of permission requests, and for apps requesting photo access, verify whether it is actually necessary for their functionality.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















