Apple has recently taken action by removing several malicious applications from the App Store, which were found to be infected with the SparkCat malware. Discovered by Kaspersky, this malware has been active since March 2024 and employs Optical Character Recognition (OCR) technology to extract sensitive information from screenshots taken by iPhone users. Specifically, it targets recovery phrases for cryptocurrency wallets. These apps leverage OCR plugins built using Google's ML Kit library to facilitate data theft and then transmit the stolen information to attackers' servers. In response, Apple has not only removed the affected apps but also blocked the developer accounts responsible. Similarly, Google has also removed these apps from its Play Store. Kaspersky strongly advises users to refrain from storing screenshots containing sensitive information in their photo libraries.
