Researchers from Kaspersky have identified malware being distributed within apps on both Android and iOS mobile storefronts. Dmitry Kalinin and Sergey Puzan shared their investigation into a malware campaign, which they have dubbed SparkCat, that has likely been active since March 2024.
“We cannot confirm with certainty whether the infection was a result of a supply chain attack or deliberate action by the developers,” the pair wrote. “Some of the apps, such as food delivery services, appeared to be legitimate, whereas others apparently had been built to lure victims.” They said SparkCat is a stealthy operation that at a glance appears to be requesting normal or harmless permissions.
On February 6, Kaspersky updated its report to note that the affected apps had been deleted from the App Store. Apple confirmed that it had removed the 11 apps, adding that the applications shared code with 89 apps that previously had been rejected or removed from the store.
The malware in question uses optical character recognition (OCR) to review a device’s photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace.”
Apple often promotes the rigorous security of the App Store, and while instances of malware appearing have been rare, this discovery is a reminder that the walled garden is not impervious to attacks.
Update, February 6, 2025, 5:15PM ET: Revised to note an update from the Kaspersky report about the apps being removed from the App Store, as well as additional context from Apple.
Trending Products

AULA Keyboard, T102 104 Keys Gaming Keyboard and Mouse Combo with RGB Backlit Quiet Laptop Keyboard, All-Steel Panel, Waterproof Gentle Up PC Keyboard, USB Wired Keyboard for MAC Xbox PC Players

Acer Aspire 3 A315-24P-R7VH Slim Laptop computer | 15.6″ Full HD IPS Show | AMD Ryzen 3 7320U Quad-Core Processor | AMD Radeon Graphics | 8GB LPDDR5 | 128GB NVMe SSD | Wi-Fi 6 | Home windows 11 Residence in S Mode

Megaccel MATX PC Case, 6 ARGB Fans Pre-Installed, Type-C Gaming PC Case, 360mm Radiator Support, Tempered Glass Front & Side Panels, Mid Tower Black Micro ATX Computer Case (Not for ATX)

Wireless Keyboard and Mouse Combo, Lovaky 2.4G Full-Sized Ergonomic Keyboard Mouse, 3 DPI Adjustable Cordless USB Keyboard and Mouse, Quiet Click for Computer/Laptop/Windows/Mac (1 Pack, Black)

Lenovo Newest 15.6″ Laptop, Intel Pentium 4-core Processor, 15.6″ FHD Anti-Glare Display, Ethernet Port, HDMI, USB-C, WiFi & Bluetooth, Webcam (Windows 11 Home, 40GB RAM | 1TB SSD)

ASUS RT-AX5400 Twin Band WiFi 6 Extendable Router, Lifetime Web Safety Included, Immediate Guard, Superior Parental Controls, Constructed-in VPN, AiMesh Appropriate, Gaming & Streaming, Sensible Dwelling

AOC 22B2HM2 22″ Full HD (1920 x 1080) 100Hz LED Monitor, Adaptive Sync, VGA x1, HDMI x1, Flicker-Free, Low Blue Mild, HDR Prepared, VESA, Tilt Modify, Earphone Out, Eco-Pleasant

Logitech MK540 Superior Wi-fi Keyboard and Mouse Combo for Home windows, 2.4 GHz Unifying USB-Receiver, Multimedia Hotkeys, 3-12 months Battery Life, for PC, Laptop computer
