14 Apr 2025

light mode

Crypto Malware Found in Google and Apple Apps Puts User Funds at Risk

A hooded figure working on a glowing red laptop with the words “Breaking News” displayed above in a cyber-themed background - The Coinomist

Cybersecurity experts at Kaspersky Lab have identified maliciously modified mobile apps designed to steal sensitive information from crypto wallets.

These apps use optical character recognition (OCR) to scan images stored in a device’s gallery, extract confidential data, and transmit it to a remote server. The threat was initially discovered by ESET researchers in March 2023, but at the time, it only affected Android and Windows users who downloaded messaging apps from unofficial sources.

However, hackers have since enhanced their attack methods, launching a new campaign known as SparkCat, which now targets both iOS and Android users via official app stores. On Google Play, these malicious apps have already been downloaded over 242,000 times, and for the App Store, this marks the first recorded instance of a data-stealing app bypassing Apple’s security measures.

According to Stephen Ajayi, dApp audit technical lead at crypto cybersecurity firm Hacken, being listed in official app stores does not guarantee security, as automated review systems often fail to detect malicious code. Hackers are also employing increasingly sophisticated programming techniques, making their malware harder to identify.

In SparkCat’s case, attackers obfuscated the entry point to hide their actions from security researchers and law enforcement. This tactic helps them evade detection while keeping their methods secret from competitors,

explained Slava Demchuk, CEO of blockchain analytics firm AMLBot.

Most malicious apps were disguised as AI-powered chat services, making them appear legitimate to unsuspecting users. Researchers believe the actual number of infected apps is likely much higher than currently reported. While Google Play and the App Store have removed most of these applications, some remain available for download.

Interestingly, the code of these malicious apps contains comments in Chinese, and server error messages also appear in Chinese. However, cybersecurity experts are hesitant to directly link these attacks to Chinese hacker groups at this stage. Moreover, these malicious programs don’t just target crypto wallet seed phrases—they also steal regular login credentials and passwords.

Related: WhiteBIT’s Cybersecurity Tips

The risk could intensify if cybercriminals start selling pre-built attack scripts or integrating AI-driven automation to enhance real-time data extraction. To reduce the risk, users should carefully manage app permissions, and avoid granting unnecessary access to files and images.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Crypto Discussions on X Today: MANTRA Crash, Solana vs. Ethereum, and more

Crypto Discussions on X Today: MANTRA Crash, Solana vs. Ethereum, and more

Mantra’s OM token plummeted over 90% within hours early on Monday. The coin raises concerns of a rug pull or major hack akin to the infamous Terra Luna coin debacle in 2023.

Lesia Dubenko
Gamification in Web3 Boosts Retention by 43%, Study by claimr and Generis

Gamification in Web3 Boosts Retention by 43%, Study by claimr and Generis

Together with Generis, a top blockchain marketing agency, claimr, an innovative Web3 quests platform, has published an analytical study on the success of initiatives for cryptocurrency projects.

Kalynychenko Yaroslav
CZ Denies Claims About Testifying Against Justin Sun

CZ Denies Claims About Testifying Against Justin Sun

Binance founder CZ refuted WSJ claims that he might testify against Justin Sun in the ongoing negotiations between the exchange and the U.S. Department of the Treasury about simplifying AML regulations.

Dmytro Psevdonimenko
World Liberty Financial Adds SEI to Its Crypto Portfolio

World Liberty Financial Adds SEI to Its Crypto Portfolio

The DeFi platform World Liberty Financial, associated with the Trump family, has added $775,000 worth of SEI tokens to its portfolio.

Dmytro Psevdonimenko
The Roundtable King: How Mario Nawfal Became Web3’s Power Connector

The Roundtable King: How Mario Nawfal Became Web3’s Power Connector

From selling blenders to hosting presidents and pariahs, Mario Nawfal reinvented himself as Web3’s boldest media voice—controversial, connected, and too big to ignore.

Elina Moskovchuk
CryptoZoo Scandal: Why Logan Paul Is Suing Coffeezilla for Defamation

CryptoZoo Scandal: Why Logan Paul Is Suing Coffeezilla for Defamation

The Logan Paul vs Coffeezilla case tests the limits of free speech, online accountability, and crypto controversy. So what really went wrong with CryptoZoo?

Vlad Vovk
Crypto Discussions on X Today: Trump’s Market Impact, New SEC Chair, & More

Crypto Discussions on X Today: Trump’s Market Impact, New SEC Chair, & More

Donald Trump’s tariff policy triggered another wave of crypto volatility—this time pushing prices up. Bitcoin is trading above $80,000, and the total crypto market cap has risen 5% in the past 24 hours.

Anahit Avetisyan
Solaxy: Scaling Solana with Layer 2 Technology

Solaxy: Scaling Solana with Layer 2 Technology

Solaxy uses L2 technology to boost Solana’s capabilities, one of the fastest blockchains in the industry. This article breaks down Solaxy’s technical features, its advantages, and its competitors.

Iaroslava Kramarenko
What Is OI? A Beginner’s Overview

What Is OI? A Beginner’s Overview

This guide explains open interest, a key metric in trading. Learn what OI is, how it works, and why it matters in futures, options, and crypto markets.

The Coinomist
How Are Cryptocurrency Hot Wallets Different from Cold Wallets?

How Are Cryptocurrency Hot Wallets Different from Cold Wallets?

A comprehensive guide comparing hot and cold crypto wallets. Learn their key security features, convenience, and costs to decide which storage suits your digital assets.

The Coinomist
Ethereum vs Bitcoin: Key Differences Explained

Ethereum vs Bitcoin: Key Differences Explained

Explore the key differences between Ethereum and Bitcoin—from their origins and technologies to their use cases and future potential. Gain a comprehensive understanding of both cryptocurrencies.

The Coinomist
Will There Be a Recession in 2025? Markets, Data, and Trump’s Tariffs

Will There Be a Recession in 2025? Markets, Data, and Trump’s Tariffs

The S&P and Nasdaq are both down hard, recession chances hit 66%, and Trump’s tariff rhetoric is shaking markets. What’s fueling the fears — and how close are we to a full-blown downturn?

Vlad Vovk
What Is a Black Swan Event and Its Impact on Crypto?

What Is a Black Swan Event and Its Impact on Crypto?

Explore the concept of a Black Swan event—a rare, unpredictable occurrence with massive impact. Learn how these events affect crypto markets and what they mean for investors.

The Coinomist
Bitcoin Stalls at $85K — Are the Bulls Losing Momentum Amid Volatility?

Bitcoin Stalls at $85K — Are the Bulls Losing Momentum Amid Volatility?

At $85,000, Bitcoin stands still—but the silence may not last. With economic instability and hesitant institutions, the stage is set for the next move.

Anton Kryshtal
Bitcoin Consolidates Near $80,000: Is a New Bottom Taking Shape?

Bitcoin Consolidates Near $80,000: Is a New Bottom Taking Shape?

Bitcoin is attempting to stabilize above the key psychological level of $80,000, but lingering economic uncertainty, a broader downtrend, and waning ETF demand continue to limit a full recovery.

Anton Kryshtal
MORE
Ukraine’s 2024 Declarations Spotlight Crypto as a New Norm

Ukraine’s 2024 Declarations Spotlight Crypto as a New Norm

2,100 Ukrainian officials, from police officers to MPs, declared crypto in 2024. BTC, USDT, and ETH are becoming standard lines in the public-sector financial life.

Elina Moskovchuk
Crypto-Anarchism: From Manifesto to Lifestyle 

Crypto-Anarchism: From Manifesto to Lifestyle 

How did crypto-anarchism evolve over 30 years from a short manifesto on paper into a lifestyle embraced by modern rebels with laptops?

Iaroslava Kramarenko
MORE