According to BlockBeats, on February 5, Kaspersky Labs reported that a malicious software development kit used for creating applications on the Google Play Store and Apple App Store is scanning user images to locate cryptocurrency wallet seed phrases, aiming to steal funds.
Kaspersky analysts Sergey Puzan and Dmitry Kalinin revealed in a report dated February 4 that once the malware, named SparkCat, infects a device, it employs an optical character recognition (OCR) stealer to search images for specific keywords in various languages.
The analysts noted, "Intruders steal the seed phrases of cryptocurrency wallets, which are sufficient to gain full control over the victim's wallet, allowing further theft of funds."
They also highlighted the malware's flexibility, stating that it can not only steal seed phrases but also extract other personal data from photo albums, such as message content or passwords that might be stored in screenshots.