Apple and Google take down malicious apps from their app stores
AppleApple(US:AAPL) TechCrunch·2025-02-11 00:45

Core Viewpoint - Apple and Google have removed 20 apps from their app stores due to the discovery of data-stealing malware known as SparkCat, which has been active since March 2024 [1][2]. Group 1: Malware Discovery and Impact - Security researchers at Kaspersky identified the SparkCat malware initially within a food delivery app in the UAE and Indonesia, later finding it in 19 other unrelated apps, which were downloaded over 242,000 times from Google's Play Store [2]. - The malware utilizes optical character recognition (OCR) to capture text on users' displays, scanning image galleries for cryptocurrency wallet recovery phrases in multiple languages [3]. - By obtaining recovery phrases, attackers can gain full control over victims' cryptocurrency wallets, leading to potential theft of funds [3]. Group 2: Response from Companies - Following the report from Kaspersky, Apple removed the compromised apps from its App Store, with Google following suit shortly after [4]. - Google confirmed that Android users were protected from known versions of the malware through the Google Play Protect security feature [5]. - Despite the removal of the apps from official stores, Kaspersky indicated that the malware might still be accessible through other websites and unofficial app stores [5].