(Apple and Google) App Store apps with screenshot-reading malware found for the first time
Says Apple app store but the same problem happens to Android.
https://www.theverge.com/news/606649/ios-iphone-app-store-malicious-apps-malware-crypto-password-screenshot-reader-found
by Wes Davis
Feb 5, 2025, 10:03 AM PST
Kaspersky says it discovered the code from this particular malware campaign, which it calls “SparkCat,” in late 2024 and that the frameworks for it appear to have been created in March of the same year.
On iOS and in some Android instances, the malware works by triggering a request to access users’ photo galleries when they attempt to use chat support within the infected app. Once permission is granted, it uses Google OCR tech, which lets it decipher text found in photos, to look for things like screenshots of crypto wallet passwords or recovery phrases. The software then sends any images it finds back to the attackers, who can then use the info to access the wallets and steal crypto.
Kaspersky says it can’t “confirm with certainty the infection was a result of a supply chain attack or deliberate action by the developers.” The company names two AI chat apps that seem to have been created for the campaign and appear to still be available on the App Store, called WeTink and AnyGPT. Additionally, Kaspersky found the malicious code in a legitimate-seeming food delivery app called ComeCome, which you can also still download.

hlthe2b
(109,015 posts)It is like sipping antifreeze daily for the sweetness and expecting nothing bad to ever happen.
BTW, the irony of Kaspersky catching this is not lost on me. While I agree that we can't take a chance given its proximity to Putin (despite Kaspersky's denials) it was once the best antivirus software hands down and I have no reason to believe that has changed--just that we can't be sure who they are protecting.
usonian
(16,915 posts)So who doesn't have a snap of their license, registration, VA card and so on?
They should go into a password manager kind of app that can't be accessed without a password or bio ID. The camera roll can be programmatically accessed.
I'm in favor of shitcanning anyone close to Putin, starting with ...
hlthe2b
(109,015 posts)Given most of these are available for hackers or officials to acquire online, I'm not sure I'm going to bother. I certainly do not have photos of passwords or online accounts of any financial nature.