New Crypto Malware Steals Screenshots of Seed Phrases — Even from Official App Stores

Moon5labs
APP1,07%

Security experts at Kaspersky are warning about a newly discovered threat targeting crypto users. A new strain of malware has emerged that steals screenshots containing wallet seed phrases, the crucial keys to accessing crypto funds.

📲 Malware Disguised as Legitimate Apps Attackers are spreading the malware through apps that look trustworthy — ranging from modified TikTok versions to crypto trackers, gambling tools, and adult content platforms. Some of the fake apps, such as Soex Wallet Tracker and Coin Wallet Pro, even managed to sneak into Google Play and Apple’s App Store, being downloaded by thousands of unsuspecting users. Often, these apps trick users into installing a special developer profile, which allows them to bypass regular phone security checks. Once installed, the app quietly requests access to the phone’s photo gallery and uses optical character recognition (OCR) to scan for seed phrases in screenshots. If detected, this sensitive data is silently sent to the attacker.

🎯 Target Region: Southeast Asia — But the Threat Is Global The malware, named SparkKitty, primarily targets users in Southeast Asia and China. It appears to be a successor to SparkCat, another campaign discovered in early 2024. In both cases, the malware shows a strong focus on accessing crypto wallets by capturing recovery phrases. The malicious apps were actively promoted via social media ads and Telegram channels. For example, Soex Wallet Tracker was downloaded over 5,000 times from Google Play before being taken down.

🧪 Kaspersky Acted Quickly — But the Risk Remains After being alerted by Kaspersky, both Apple and Google removed the malicious apps from their stores. However, researchers say the campaign has likely been active since April 2024, with traces dating back even further. This means similar malware could reappear, using the same methods but under new names.

#CryptoSecurity , #CyberSecurity , #HackerAlert , #HackerNews , #StaySafe

Stay one step ahead – follow our profile and stay informed about everything important in the world of cryptocurrencies! Notice: ,The information and views presented in this article are intended solely for educational purposes and should not be taken as investment advice in any situation. The content of these pages should not be regarded as financial, investment, or any other form of advice. We caution that investing in cryptocurrencies can be risky and may lead to financial losses.“

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments