{
    "success": true,
    "data": {
        "id": 1658653,
        "msgid": "beware-of-sparkcat-malware-on-app-store-and-google-play-targeting-crypto-assets-1775631142",
        "date": "2026-04-06 15:36:00",
        "title": "Beware of SparkCat Malware on App Store and Google Play Targeting Crypto Assets",
        "author": "Putri Rosmalia",
        "source": "MEDIA_INDONESIA",
        "tags": "",
        "topic": "Technology",
        "summary": "Security researchers at Kaspersky have identified a new variant of the SparkCat Trojan malware infiltrating legitimate apps on the App Store and Google Play to steal users' cryptocurrency assets, particularly by scanning photo galleries for wallet recovery phrases. This evolved threat, which re-emerged after a year, employs advanced obfuscation techniques, OCR for text recognition in images, and machine learning to evade detection, highlighting the ongoing evolution of cyber threats. Users handling digital currencies are urged to exercise greater caution in managing sensitive recovery data to avoid digital theft.",
        "content": "<p>Security on official platforms such as the App Store and Google Play\nhas once again come under sharp scrutiny. Kaspersky security researchers\nhave recently identified a new variant of the SparkCat Trojan malware,\nwhich has the capability to infiltrate legitimate applications to steal\nusers\u2019 crypto assets.<\/p>\n<p>A year after it was first discovered and temporarily removed,\nSparkCat has reappeared with far more sophisticated techniques. The\nmalware disguises itself within seemingly legitimate apps, ranging from\nfood delivery services to corporate communication applications, to\nsilently scan users\u2019 photo galleries.<\/p>\n<p>SparkCat\u2019s primary target is the recovery phrases (seed phrases) for\nRupiah digital currency wallets or other highly sensitive crypto assets.\nExperts have found at least two apps on the App Store and one on Google\nPlay that have been compromised by this malicious code.<\/p>\n<p>In addition to official channels, SparkCat distribution has been\ndetected through third-party sources. One method involves fake websites\nthat identically mimic the App Store interface when accessed via iPhone\ndevices.<\/p>\n<p>This attack is designed with specific geographical targeting:<\/p>\n<p>Updates to SparkCat on the Android platform demonstrate significant\ntechnical complexity. The malware is now equipped with multiple layers\nof obfuscation, including code virtualisation and cross-platform\nprogramming languages.<\/p>\n<p>Sergey Puzan, a cybersecurity expert at Kaspersky, explained that the\nmalware utilises an optical character recognition (OCR) module to\nanalyse text in images stored on the phone. \u201cIf relevant keywords are\nfound, the image is immediately sent to the hackers,\u201d he stated.<\/p>\n<p>Dmitry Kalinin, Puzan\u2019s colleague at Kaspersky, added that the\nperpetrators are consistently enhancing the complexity of their\nanti-analysis techniques. This is what allows SparkCat to bypass the\nrigorous review processes on Apple and Google\u2019s official app stores.<\/p>\n<p>The return of the SparkCat Trojan malware serves as a reminder that\ncyber threats continue to evolve. Users of crypto assets are advised to\nbe more cautious in managing their digital wallet recovery data to avoid\nfalling victim to digital asset theft.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/beware-of-sparkcat-malware-on-app-store-and-google-play-targeting-crypto-assets-1775631142",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}