
Researchers at Kaspersky have uncovered a new mobile malware campaign named SparkKitty that steals cryptocurrency wallet seed phrases by capturing screenshots stored on iOS and Android devices. Utilizing advanced OCR technology, SparkKitty infiltrates popular app stores through disguised apps such as modified TikTok versions and crypto portfolio trackers. The malware exploits enterprise provisioning on iOS and injects malicious code into Android apps to bypass security, quietly extracting sensitive wallet data. Additionally, it employs social engineering tactics to coax users into revealing seed phrases. This threat highlights the need for crypto users to avoid storing sensitive information in screenshots and to maintain strong device security.
Continue to read
SparkKitty Malware Targets Crypto Wallet Seed Phrases via Mobile Screenshots on iOS and Android
Yorumlar
Yorum Gönder