216.73.217.80

Take my money: OCR crypto stealers in Google Play and App Store

· Published 05/02/2025 14:55 · Modified 05/02/2025 21:47

Export JSON

Essential information

Published
05/02/2025 14:55
Modified
05/02/2025 21:47
Tags
2025-02-05 android app stores crypto-stealer ios mobile malware ocr sparkcat
Related entities
2 techniques (mitre), 1 malware, 6 others

Description

Researchers discovered a new malware campaign dubbed '' targeting and users through both official and unofficial . The malware, embedded in various apps, uses technology to scan users' image galleries for crypto wallet recovery phrases. Infected apps on Google Play had over 242,000 downloads. This marks the first known case of such a stealer in Apple's App Store. The malware employs Google's ML Kit for and communicates with C2 servers using a custom protocol implemented in Rust. It targets users in Europe and Asia, searching for keywords related to crypto wallets in multiple languages. The campaign has been active since March 2024, demonstrating sophisticated techniques to evade detection.

External references