SparkCat malware Warning for Crypto Money

NGUYỄN ĐĂNG |

bus (malicious code) called SparkCat has been active on the App Store and Google Play since March 2024, which can steal data and cryptocurrency.

Kaspersky's Center for Cyber ​​Security has found this malware (malware) based on optical identity that appears on the App Store. Sparkcat uses machine learning technology to scan a photo library and steal screenshots containing phrases restoring cryptocurrencies. Sparkcat can also find and extract other sensitive data in images, such as passwords.

How to spread new malware

The Malware is not only hidden in infected legal applications with malware, but also in bait applications such as messaging apps, AI assistants, food delivery, applications related to cryptocurrencies, etc.

Some apps can be downloaded from official platforms on Google Play and App Store. Kaspersky's remote measurement data also shows that app versions contaminated with malware are also distributed through unofficial sources. On Google Play, these apps have been downloaded more than 242,000 times.

Who was the target attacked by this malware?

Malware mainly targets users in the UAE and countries in Europe and Asia. This is the conclusion of experts based on information about the operating areas of applications infected with malware and technical analysis of malware.

Accordingly, SparkCat scanned the photo library to find keywords in many languages, including Chinese, Japanese, Korean, English, Czech, French, Italian, Polish and Portuguese. However, experts believe that the victims may also come from other countries.

How SparkCat works

According to the scenario, after being installed on the device, this malware will require access to the user's photo library to view all images. After that, this malware will use a optical signature (OCR) recognition module to analyze text and signatures in images. If the stolen words were discovered, SparkCat would send the image to the attackers.

hackers' main goal is to find words to restore cryptocurrency wallets. With this information, bad guys can completely control the victim's wallet and steal money. In addition to stealing restored phrases, this malware also has the ability to extract other personal information from screenshots, such as text messages and passwords.

To avoid becoming victims of this malware, Kaspersky cybersecurity experts recommend the following safety measures:

- If you have installed one of the malware-infected applications, delete them immediately from the device and do not reuse them until there is an update to fix the problem.

- Avoid storing screenshots containing sensitive information in the photo library, including the phrase restoring cryptocurrencies. Passwords should be stored in specialized security applications.

- Use reliable security software to prevent the risk of malware.

NGUYỄN ĐĂNG
TIN LIÊN QUAN

Apple's iPad continues to dominate the tablet market

|

Apple's iPad continues to dominate the tablet market with 42.3% of the global market share in the fourth quarter of 2024.

Malware variant targeting banks discovered

|

Variants of the Grandoreiro malware are becoming one of the major threats worldwide.

Salary plan when removing district level, rearranging commune level

|

Regarding salaries, Minister Pham Thi Thanh Tra emphasized the need to calculate and ensure connectivity when implementing the arrangement of administrative units.

Russia reclaims largest city in Kursk province

|

Russia has retaken Sudzha - the largest city controlled by Ukraine in Russia's Kursk region - amid pressure on negotiations to end the conflict.

Bac Ninh names 5 projects causing great loss and waste

|

Bac Ninh - The Provincial People's Committee has just named 5 projects that are behind schedule, have long backlogs, and are ineffective, causing great loss and waste.

The fate of parking lots in Ho Chi Minh City when stopping district police

|

HCMC - The City Police rearranged warehouses and parking lots for violations after the end of the operation of district and county police, and increased fire prevention and fighting work.

311 teachers unexpectedly have their insurance money collected VND4.6 billion

|

Nghe An - 311 teachers were charged VND4.6 billion in insurance, including more than VND2.6 billion in fines for late payment.

Workshop on the life and revolutionary career of comrade Nguyen Thi Dinh

|

Ben Tre - The scientific seminar "The life and revolutionary career of comrade Nguyen Thi Dinh" will be held in Ben Tre on March 15, 2025.

Apple's iPad continues to dominate the tablet market

TRÍ MINH (THEO macrumors) |

Apple's iPad continues to dominate the tablet market with 42.3% of the global market share in the fourth quarter of 2024.

Những cuộc tấn công mã độc khiến doanh nghiệp Việt điêu đứng

KHÁNH AN |

Năm 2024, hàng loạt doanh nghiệp lớn tại Việt Nam bị tấn công mạng, gây thiệt hại và làm gián đoạn các dịch vụ trực tuyến.

Malware variant targeting banks discovered

NGUYỄN ĐĂNG |

Variants of the Grandoreiro malware are becoming one of the major threats worldwide.