• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Kaspersky discovers new SparkCat variant bypassing App Store and Google Play security

by CXO Staff
April 8, 2026
in Future, News, Tech

Kaspersky has identified a new variant of the SparkCat Trojan in the App Store and Google Play

Kaspersky discovers new SparkCat variant bypassing App Store and Google Play security

Kaspersky has identified a new variant of the SparkCat Trojan in the App Store and Google Play—a year after the crypto-stealing malware was first discovered and removed from both platforms. The Trojan hides inside legitimate-looking apps and scans users’ photo galleries for cryptocurrency wallet recovery phrases.

The new version of SparkCat is distributed through infected legitimate apps—a messenger designed for enterprise communication and a food delivery app. Kaspersky experts found two infected apps on the App Store and one on Google Play, from which the malicious code has since been removed. Kaspersky telemetry shows that the apps infected with SparkCat are also distributed through third-party sources. A few of these web pages are mimicking the App Store if opened from an iPhone.

The updated variant of the Trojan for Android scans image galleries on the compromised devices for screenshots containing specific keywords in Japanese, Korean, and Chinese, leading Kaspersky experts to assess that this campaign primarily targets cryptocurrency assets of users in Asia. The iOS variant, however, takes a different approach as it scans for cryptocurrency wallet mnemonic phrases, which are in English. This makes the iOS variant potentially broader in reach, as it can affect users regardless of their region. 

The updated SparkCat version for Android features multiple obfuscation layers compared to previous versions, including code virtualisation and cross-platform programming language usage — techniques that are rare for mobile malware.

Kaspersky has reported known malicious applications to Google and Apple.

The infected version of the app for iOS

“The updated variant of SparkCat requests access to view photos in a user’s smartphone gallery in certain scenarios—just like the very first version of the Trojan. It analyses the text in stored images using an optical character recognition module. If the stealer finds relevant keywords, it sends the image to the attackers. Considering the similarities of the current sample and the previous one, we believe that the developers of the new version of malware are the same. This campaign again underscores the importance of using security solutions for smartphones to stay protect against a broad range of cyberthreats,” said Sergey Puzan, cybersecurity expert at Kaspersky.  

“The SparkCat malware is an evolving mobile threat. Threat actors behind it constantly raise the complexity of the anti-analysis techniques, allowing it to bypass the review process of the official app stores. Moreover, methods used by the SparkCat developers, such as code virtualisation and cross-platform programming language usage, are rare for mobile malware. This demonstrates the high skill of the threat actors,” added Dmitry Kalinin, cybersecurity expert at Kaspersky.

To avoid becoming a victim of this malware, Kaspersky recommends the following safety measures:

  • Use reliable cybersecurity software, like Kaspersky for Mobile — it can protect your data on smartphones from cyberattacks. Kaspersky for Android will prevent installation of the malware, while Kaspersky for iOS, due to the architectural characteristics of Apple’s OS, prevents an attempt to connect to the attackers’ command server and displays a warning to users. 
  • Avoid storing screenshots containing sensitive information in your gallery, especially cryptocurrency wallet seed phrases. Such sensitive information as well as screenshots of important documents should be stored in specialised applications such as Kaspersky Password Manager.
  • Be careful even downloading apps from official stores, as it is not always risk-free.

Tags: KasperskySparkCat
ShareTweet

Related Posts

Almosafer launches Saudi’s first ChatGPT-integrated travel app
Future

Almosafer launches Saudi’s first ChatGPT-integrated travel app

April 8, 2026

Almosafer Travel & Tourism announced it has officially launched on the ChatGPT platform, becoming the first application from the Kingdom...

Acronis launches 24x7x365 MDR service
Future

Acronis launches 24x7x365 MDR service

April 8, 2026

Acronis has announced the launch of Acronis MDR by Acronis TRU, a globally available 24/7/365 managed detection and response (MDR) service....

Discussion about this post

Latest Issue

Almosafer launches Saudi’s first ChatGPT-integrated travel app

Almosafer launches Saudi’s first ChatGPT-integrated travel app

April 8, 2026
Acronis launches 24x7x365 MDR service

Acronis launches 24x7x365 MDR service

April 8, 2026
VAST Data launches Polaris

Nutanix delivers complete platform for the Agentic AI era

April 8, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.