After an investigation in official iOS and Android Applications stores, Kaspersky’s security analysts have encountered a new spy Trojan baptized as Sparkkitty, capable of stealing information and images of the infected mobile.
This Trojan, as experts point out after the technical analysis, could be related to another malware already known throughout this year, such as Sparkcat, the first malware in iOS with an integrated optical recognition module (OCR) integrated.
Thanks to OCR, I could scan the image galleries of the infected device, in addition to RObar screenshots with recovery phrasesas well as passwords of cryptocurrency purses.
Kaspersky
In this way, Sparkkitty has been distributed through various applications available in the iOS app
As if that were not enough, this Trojan has also been identified in other bets of bets that have appeared in the App Store and, what is more worrying, in Malicious versions that mimic one of the most downloaded platforms, Tiktok.
«In the infected version of Tiktok, the malware not only steals the photos of the device gallery during the login, but also adds links to a suspicious store in the user’s profile,» explained Sergey Puzan, Kaspersky malware expert.
«This store only accepts payments in cryptocurrencies, which reinforces our suspicions about its true purpose,» he added.
That is, the attackers have used false websites to deceive their victims, since IOS allows the installation of apps out of the official store through legitimate roads, such as developers used to distribute corporate apps.
Unfortunately, Kaspersky’s security analysts have assured Secure List that they have discovered several apps related to artificial intelligence in iOS associated with malware, many more than those who thought, in addition to the fact that the Trojan could act differently according to the app in question.
On the other hand, on Android, the attackers have used different social platforms, including YouTube, to offer their infected APK files, with the ability to steal the data of the infected device.
Interestingly, apps work as explained in the description, although at the same time They send photos of the mobile gallery to the cybercriminalsaccording to Dimitry Kalinin, Kaspersky malware expert.

Kaspersky
«There are several indications that the attackers are looking for digital assets specifically: many of the infected apps are related to cryptocurrencies, and Tiktok’s troyanized version includes an integrated store that only accepts cryptocurrency payments,» he added to the analyst.
As Kalinin explains and Puzan in the detailed technical report of the investigation, it seems that the attackers are in Asia and Europe, not only by the identified victims, but because part of the malicious code is found in Chinese fluidat least on Android.
However, they also specify that they have not been able to reach a clear conclusion about who is behind these attacks. If you have downloaded any of the apps mentioned in Secure List, check your mobile and completely uninstall any version.
Know How we work in NoticiasVE.
Tags: Malware, iOS, play store, cybersecurity
