Skip to main content

Screenshot-reading malware cracks iPhone security for the first time

A person holding an iPhone in their hand.
Bagus Hernawan / Unsplash

In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

Recommended Videos

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

An app listed on the App Store infected by malware.
Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

One of the iPhone apps infected by OCR malware.
Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.

Nadeem Sarwar
Nadeem is a tech and science journalist who started reading about cool smartphone tech out of curiosity and soon started…
Here’s a big reason the ‘iPhone Fold’ will look like an iPad
Concept render of a foldable iPhone in a fully open state.

Apple is expected to launch its first “iPhone Fold” in 2026, several years after rival companies like Samsung and OnePlus have already released their own foldable devices. The reason for Apple’s delay in entering the foldable market is not entirely clear. However, one plausible explanation is that Apple has focused on ensuring the device offers a seamless transition between the outer and inner displays.

This week, it was reported that Apple plans to use a liquid metal hinge in the iPhone Fold. This innovation aims to enhance durability and reduce the visibility of the display crease. Creasing was a significant issue for early foldable devices, such as the first Samsung Galaxy Z Fold, but it has improved considerably over the years.

Read more
iPhone now lets you make WhatsApp your default for messages and calls, here’s how
WhatsApp.

iPhone users can now get setup so that WhatsApp is their default messaging and calling app.

If your iPhone is updated to iOS 18.2 then the functionality is already available for you right now.

Read more
Top Apple analyst suggests the iPhone Mini is truly extinct
the best call recording apps for iphone 12 mini case feature image copy

Earlier this year, Apple released the iPhone 16E and put an end to the iPhone SE lineup. For those who had hopes the iPhone Mini might return, that doesn't seem likely either. In a Q&A session with Mark Gurman, the analyst said Apple doesn't have plans to bring the miniature version of its iconic lineup back anytime soon.

That's not exactly surprising. Apple basically killed the iPhone Mini lineup in 2023 when it launched the iPhone 14 Plus, leaving the iPhone 13 Mini as the last of its kind. With a 5.4-inch display, the iPhone 13 Mini wouldn't exactly fit in today's market of larger screens, but for users that preferred smaller phones, it was a godsend.

Read more