New malware targets users on App Store and Google Play

NGUYỄN ĐĂNG |

Experts have just discovered a new type of malware called SparkKitty, designed to attack smartphones using iOS and Android operating systems.

Regarding the attack method, after the malware has entered the user's phone, it sends images and device information from the infected phone to the attacker's server. SparkKitty is installed in apps with content related to cryptocurrency, gambling, as well as in a fake version of the TikTok app.

These applications are distributed not only through the App Store and Google Play, but also on fraudulent websites. According to experts' analysis, the goal of this campaign could be to steal cryptocurrency from users in Southeast Asia and China. Users in Vietnam are also at risk of facing a similar threat.

Kaspersky cybersecurity experts have sent notices to Google and Apple to handle the above malicious applications. Some technical details show that this new attack campaign is related to SparkCat - a Trojan that was discovered earlier.

SparkCat is the first malware on the iOS platform to have an integrated optical character recognition (OCR) modular to scan users' photobooks, steal screenshots containing passwords or phrases to restore cryptocurrency wallets.

On the App Store, this Trojan malware is disguised as a cryptocurrency-related application called " Economiccoin. In addition, on fraudulent websites designed to fake the iPhone App Store interface, cybercriminals also spread this malware under the cover of the TikTok application and some betting games.

On the Android operating system, attackers target users on both Google Play and third-party websites, by disguising malware as cryptocurrency-related services.

One example of a malware-infected application is SOEX - a messaging application with integrated cryptocurrency trading functions, with more than 10,000 downloads from the official store.

In addition, experts also discovered APK files ( Android application instalments, which can be installed directly without Google Play) of these malware-infected applications on third-party websites, which are believed to be related to the above attack campaign.

These apps are being promoted in the form of cryptocurrency investment projects. Notably, websites that distribute apps are also widely promoted on social networks, including YouTube.

To avoid becoming a victim of this malware, experts recommend that users take the following safety measures:

- If you have successfully installed one of the malware-infected apps, quickly remove the app from your device and do not reuse it until an official update is available to completely remove the malware feature.

- Avoid storing screenshots containing sensitive information in the photo library, especially images with code to restore cryptocurrency wallets. Instead, users can store login information in specialized password management applications.

- Set up trusted security software, for example, to prevent the risk of malware infection.

- When an application requires access to a photo library, users should carefully consider whether this permission is really necessary for the application's main functions.

NGUYỄN ĐĂNG
RELATED NEWS

Things to do as soon as a smartphone is infected with malware, self-made advertisements

|

Smartphones that are constantly advertising and install strange applications themselves are signs of malware. Early processing helps protect data and avoid losing control of personal devices.

malware steals data, leaks 2.3 million bank cards

|

According to an estimate from Kaspersky Digital footprint Intelligence, up to 2.3 million bank cards have been leaked on the dark web due to malware.

Apple and Google remove apps containing data-stealing malware

|

Apple and Google have removed apps containing data-stealing malware from their app stores.

Origin of nearly 30kg of gold that Ha Tinh announced sold for more than 142 billion VND

|

Ha Tinh - The Department of Finance has just announced the sale of nearly 30kg of gold established for all-people ownership originating from confiscated exhibits from an illegal transportation case.

Head of the Supreme People's Procuracy talks about 5 key task groups of the Procuracy sector

|

In meetings with voters in 15 wards and communes of Quang Tri province, Chief Procurator of the Supreme People's Procuracy Nguyen Huy Tien shared his thoughts with the people.

Dien Bien warns of extremely dangerous forest fires

|

Dien Bien - Many communes and wards in the province warn of extremely dangerous forest fires (Level V).

Ministry of Industry and Trade: Petroleum enterprises are not allowed to hoard goods, not to sell sparingly

|

The Ministry of Industry and Trade requests gasoline and oil enterprises not to hoard goods, not to sell cautiously waiting for prices to increase, and to proactively maintain supply for the distribution system.

Cargo ship collides with Ghenh bridge on Dong Nai River

|

Dong Nai - At about 10 am on March 6, a cargo ship collided with Ghenh bridge.

Things to do as soon as a smartphone is infected with malware, self-made advertisements

Cát Tiên (T/H) |

Smartphones that are constantly advertising and install strange applications themselves are signs of malware. Early processing helps protect data and avoid losing control of personal devices.

malware steals data, leaks 2.3 million bank cards

NGUYỄN ĐĂNG |

According to an estimate from Kaspersky Digital footprint Intelligence, up to 2.3 million bank cards have been leaked on the dark web due to malware.

Apple and Google remove apps containing data-stealing malware

TRÍ MINH (THEO techcrunch) |

Apple and Google have removed apps containing data-stealing malware from their app stores.