Screenshot-reading malware cracks iPhone security for the first time

In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

Recommended Videos

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.

Please enable Javascript to view this content

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.

Editors’ Recommendations

  • Samsung aped iPhone filters, but served it better on the Galaxy S25

  • There’s a clear winner in our Galaxy S25 Ultra vs iPhone 16 Pro Max camera test

  • iPhone SE 4: everything we know so far

  • Microsoft is making a major change to using your iPhone in Windows

  • The next iPhone may have this design feature after all




Related posts

Latest posts

ChromeOS 134 preview teases accessibility features, quick insert improvements

The chromeOS.dev team has shared notes on upcoming features for the ChromeOS 134 update, which is set to release on Monday.

Apple’s AI plans for Siri hit major roadblocks behind the scenes

A Bloomberg report indicates that Apple team leads are discussing the state of the Siri AI project internally and trying to reassure staff of its progress.

I tried Foto, the anti-Instagram, and it’s both wonderful and intimidating

After becoming disillusioned with Instagram, I tried new photo sharing app Foto. What I found was both wonderfully simple, but also quite intimidating.

Kobo Clara BW review: It’s great, but I don’t know why it exists

The Kobo Clara BW is an excellent black and white e-reader, and usually, it would be an easy recommendation. However, I can't recommend you buy it.

Gemini is replacing Google Assistant. How will the shift affect you?

Google Assistant will ride into the sunset soon, and Gemini will replace it on all your devices. Here’s everything you need to know about how the shift happens.

Samsung’s upcoming Fan Edition tablets might test fans’ patience

Samsung’s upcoming Galaxy Tab S10 FE series tablets will reportedly hit buyers with a price hike, while serving one less camera and no iterative memory upgrade.

Why the Infinix tri-fold excites me more than the Huawei Mate XT

Surprised or disgusted by my take? Hear me out. I have one very good reason why the Infinix tri-fold is

News Weekly: Massive Pixel 10 leak, March update chaos, OnePlus ditching its Alert Slider, and more

This week we dive into a massive Pixel 10 leak that showed off all three models, Pixel users are scrambling

Encrypted RCS messages between platforms are coming, but this won’t end the messaging wars

It was never about encryption; it was about locking you in.

I tested the 12-year-old Lumia 1020 against my favorite Android smartphone camera. Here’s how it went

After roughly 12 years, I took the Nokia Lumia 1020 and pit its 41MP camera against the OnePlus 12.