Indonesian Political, Business & Finance News

Beware of SparkCat Malware on App Store and Google Play Targeting Crypto Assets

| | Source: MEDIA_INDONESIA Translated from Indonesian | Technology
Beware of SparkCat Malware on App Store and Google Play Targeting Crypto Assets
Image: MEDIA_INDONESIA

Security on official platforms such as the App Store and Google Play has once again come under sharp scrutiny. Kaspersky security researchers have recently identified a new variant of the SparkCat Trojan malware, which has the capability to infiltrate legitimate applications to steal users’ crypto assets.

A year after it was first discovered and temporarily removed, SparkCat has reappeared with far more sophisticated techniques. The malware disguises itself within seemingly legitimate apps, ranging from food delivery services to corporate communication applications, to silently scan users’ photo galleries.

SparkCat’s primary target is the recovery phrases (seed phrases) for Rupiah digital currency wallets or other highly sensitive crypto assets. Experts have found at least two apps on the App Store and one on Google Play that have been compromised by this malicious code.

In addition to official channels, SparkCat distribution has been detected through third-party sources. One method involves fake websites that identically mimic the App Store interface when accessed via iPhone devices.

This attack is designed with specific geographical targeting:

Updates to SparkCat on the Android platform demonstrate significant technical complexity. The malware is now equipped with multiple layers of obfuscation, including code virtualisation and cross-platform programming languages.

Sergey Puzan, a cybersecurity expert at Kaspersky, explained that the malware utilises an optical character recognition (OCR) module to analyse text in images stored on the phone. “If relevant keywords are found, the image is immediately sent to the hackers,” he stated.

Dmitry Kalinin, Puzan’s colleague at Kaspersky, added that the perpetrators are consistently enhancing the complexity of their anti-analysis techniques. This is what allows SparkCat to bypass the rigorous review processes on Apple and Google’s official app stores.

The return of the SparkCat Trojan malware serves as a reminder that cyber threats continue to evolve. Users of crypto assets are advised to be more cautious in managing their digital wallet recovery data to avoid falling victim to digital asset theft.

View JSON | Print