Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    A Century of Care and Craftsmanship: History of the Holy Kaaba’s Kiswa in the Saudi Era

    June 17, 2026

    AI infrastructure growth is rewriting rules of data centre design, says Equinix MENA MD 

    June 17, 2026

    New UAE rule may inspire more Emiratis to study medicine, join healthcare sector

    June 17, 2026
    Facebook X (Twitter) Instagram
    Riyadh Week
    • Home
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    Facebook X (Twitter) Instagram YouTube
    Riyadh Week
    Home»Technology»Kaspersky discovers Trojan variant bypassing App Store and Google Play security
    Technology

    Kaspersky discovers Trojan variant bypassing App Store and Google Play security

    Editorial TeamBy Editorial TeamApril 14, 2026
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Kaspersky has recently identified a new variant of the SparkCat Trojan in the App Store and Google Play—a year after the crypto-stealing malware was first discovered and removed from both platforms.

    The Trojan hides inside legitimate-looking apps and scans users’ photo galleries for cryptocurrency wallet recovery phrases.

    The new version of SparkCat is distributed through infected legitimate apps—a messenger designed for enterprise communication and a food delivery app. Kaspersky experts found two infected apps on the App Store and one on Google Play, from which the malicious code has since been removed. Kaspersky telemetry shows that the apps infected with SparkCat are also distributed through third-party sources. A few of these web pages are mimicking the App Store if opened from an iPhone.

    The updated variant of the Trojan for Android scans image galleries on the compromised devices for screenshots containing specific keywords in Japanese, Korean, and Chinese, leading Kaspersky experts to assess that this campaign primarily targets cryptocurrency assets of users in Asia. The iOS variant, however, takes a different approach as it scans for cryptocurrency wallet mnemonic phrases, which are in English. This makes the iOS variant potentially broader in reach, as it can affect users regardless of their region.

    The updated SparkCat version for Android features multiple obfuscation layers compared to previous versions, including code virtualization and cross-platform programming language usage — techniques that are rare for mobile malware.

    Kaspersky has reported known malicious applications to Google and Apple.

    “The updated variant of SparkCat requests access to view photos in a user’s smartphone gallery in certain scenarios—just like the very first version of the Trojan. It analyses the text in stored images using an optical character recognition module. If the stealer finds relevant keywords, it sends the image to the attackers. Considering the similarities of the current sample and the previous one, we believe that the developers of the new version of malware are the same. This campaign again underscores the importance of using security solutions for smartphones to stay protect against a broad range of cyberthreats”, said Sergey Puzan, cybersecurity expert at Kaspersky.

    “The SparkCat malware is an evolving mobile threat. Threat actors behind it constantly raise the complexity of the anti-analysis techniques, allowing it to bypass the review process of the official app stores. Moreover, methods used by the SparkCat developers, such as code virtualisation and cross-platform programming language usage, are rare for mobile malware. This demonstrates the high skill of the threat actors”, added Dmitry Kalinin, cybersecurity expert at Kaspersky.

    To avoid becoming a victim of this malware, Kaspersky recommends the following safety measures:

    • Use reliable cybersecurity software, like Kaspersky for Mobile — it can protect your data on smartphones from cyberattacks. Kaspersky for Android will prevent installation of the malware, while Kaspersky for iOS, due to the architectural characteristics of Apple’s OS, prevents an attempt to connect to the attackers’ command server and displays a warning to users.
    • Avoid storing screenshots containing sensitive information in your gallery, especially cryptocurrency wallet seed phrases. Such sensitive information as well as screenshots of important documents should be stored in specialized applications such as Kaspersky Password Manager.
    • Be careful even downloading apps from official stores, as it is not always risk-free.

    Image Credit: Kaspersky


    Source: Tahawul Tech

    Related Posts

    AI infrastructure growth is rewriting rules of data centre design, says Equinix MENA MD 

    June 17, 2026

    Dubai Chamber supports launch of 32 Apps via Create Apps Accelerator Programme

    June 17, 2026

    Cisco reports on AI network pressures

    June 17, 2026
    Top Posts

    QBS Software Middle East embeds AI into core operations

    April 1, 2026

    Bosnia’s Barbarez cool as ice after reaching World Cup in shootout with Italy

    April 1, 2026

    Kuwaiti tanker hit by Iranian drone attack in Dubai waters

    April 1, 2026

    UAE designers turn jewellery into meaningful Eid gifts

    April 1, 2026
    Don't Miss

    A Century of Care and Craftsmanship: History of the Holy Kaaba’s Kiswa in the Saudi Era

    By Editorial TeamJune 17, 2026

    For more than a century, the Holy Kaaba’s Kiswa has been one of the most…

    AI infrastructure growth is rewriting rules of data centre design, says Equinix MENA MD 

    June 17, 2026

    New UAE rule may inspire more Emiratis to study medicine, join healthcare sector

    June 17, 2026

    Al-Harth Municipality Walkway Emerges as Tourist Destination Showcasing Jazan’s Mountain Beauty

    June 17, 2026
    • KSA
    • Business
    • Technology
    • Lifestyle
    • Sports
    2026. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.