According to Foresight News, cybersecurity firm Kaspersky Labs has identified a new malware activity named SparkCat, discovered at the end of 2024. The attackers aim to use Optical Character Recognition (OCR) to steal mnemonic phrases, allowing them to regain access to cryptocurrency wallets and potentially take full control to further steal funds. Applications infected with this malware have been found on both Google Play and the App Store. It remains unclear whether these apps were compromised through a supply chain attack or if developers intentionally embedded the Trojan. Over 242,000 downloads of the infected applications have been recorded from Google Play alone. SparkCat has been active since March 2024.
Kaspersky Labs advises users to remove any infected applications from their devices and refrain from using them until patches addressing the malicious features are released. Additionally, users are cautioned against storing screenshots containing sensitive information.