Apr 03, 2026 • [email protected] (The Hacker News)
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images
A new variant of the SparkCat trojan has been discovered on both the Apple App Store and Google Play Store, more than a year after its initial detection. The...
Executive Summary
A new variant of the SparkCat trojan has been discovered on both the Apple App Store and Google Play Store, more than a year after its initial detection. The malware disguises itself as legitimate applications including enterprise messengers and food delivery services to evade detection. Once installed, SparkCat uses optical character recognition (OCR) to scan device images and steal cryptocurrency wallet recovery phrases, enabling attackers to gain full access to victims' crypto assets. Users are advised to review app permissions, avoid storing sensitive information in photo galleries, and verify the legitimacy of applications before download to mitigate this threat.
Summary
Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as enterprise messengers and food delivery services, while
Published Analysis
A new variant of the SparkCat trojan has been discovered on both the Apple App Store and Google Play Store, more than a year after its initial detection. The malware disguises itself as legitimate applications including enterprise messengers and food delivery services to evade detection. Once installed, SparkCat uses optical character recognition (OCR) to scan device images and steal cryptocurrency wallet recovery phrases, enabling attackers to gain full access to victims' crypto assets. Users are advised to review app permissions, avoid storing sensitive information in photo galleries, and verify the legitimacy of applications before download to mitigate this threat. Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as enterprise messengers and food delivery services, while Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as enterprise messengers and food delivery services, while
Linked Entities
- SparkCat