Navigation
Recherche
|
First OCR Spyware Breaches Both Apple and Google App Stores To Steal Crypto Wallet Phrases
mercredi 5 février 2025, 21:42 , par Slashdot
This marks the first known instance of such OCR-based spyware making it into Apple's App Store. The malware, active since March 2024, masquerades as an analytics SDK called 'Spark' and leverages Google's ML Kit library to scan users' photos for wallet recovery phrases in multiple languages. It requests gallery access under the guise of allowing users to attach images to support chat messages. When granted access, it searches for specific keywords related to crypto wallets and uploads matching images to attacker-controlled servers. The researchers found both Android and iOS variants using similar techniques, with the iOS version being particularly notable as it circumvented Apple's typically stringent app review process. The malware's creators appear to be Chinese-speaking actors based on code comments and server error messages, though definitive attribution remains unclear. Read more of this story at Slashdot.
https://it.slashdot.org/story/25/02/05/1826259/first-ocr-spyware-breaches-both-apple-and-google-app-...
Voir aussi |
56 sources (32 en français)
Date Actuelle
jeu. 6 févr. - 00:43 CET
|