Skip to main content

Screenshot-reading malware cracks iPhone security for the first time

A person holding an iPhone in their hand.
Bagus Hernawan / Unsplash

In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

Recommended Videos

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

An app listed on the App Store infected by malware.
Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

One of the iPhone apps infected by OCR malware.
Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.

Nadeem Sarwar
Nadeem is a tech and science journalist who started reading about cool smartphone tech out of curiosity and soon started…
This one iPadOS 26 feature has me excited for the iPhone Fold
Semi-open state of a foldable iPhone concept

Samsung is set to launch the seventh generation of its Galaxy Z Fold book-style folding phone this Summer, but its biggest rival is yet to show its folding phone hand. Apple has long been expected to unveil an iPhone Fold, and the latest rumors suggest that it will launch next year.

I’ve used almost every folding phone released globally, with some exceptions for extremely obscure ones. While I've always been curious what an iPhone Fold would look like, I was fairly certain that Apple shouldn't build it, as I wasn’t sure they could deliver on one necessary feature.

Read more
These three iOS 26 beta features are my favorite so far
The Liquid Design lock screen on the iOS 26 developer beta 1 running on the iPhone 16 Pro

For fans of the Apple ecosystem, it’s been an incredible week. Apple’s annual WWDC 2025 keynote revealed a whole new Liquid Glass design that’s unified across all its platforms. Also unified across all platforms is the numbering scheme, with iOS 26 designed to represent the year of release… plus one. 

The new platform doesn’t deliver one of the key things I asked for — multitasking, which is available on iPadOS 26 — but it does bring several new features that make the iPhone far more usable. 

Read more
Will my iPhone get iOS 26? Here’s every supported model
We've got the full list of iOS 26 supported devices - find out if you're getting the new iPhone update
iOS 26 features on a series of iPhone screens

Apple announced iOS 26 at WWDC 2025, and the new iPhone update comes with a fresh new 'Liquid Glass' look and plenty of features - and there are loads of iOS 26 supported devices, which is great news.

And no, you haven't missed a volley of updates since iOS 18 in 2024. Apple has skipped a bunch of numbers, so instead of giving us iOS 19 in 2025, we got iOS 26 alongside iPadOS 26, macOS 26, watchOS 26 and tvOS 26. In short, Apple's brought its operating system numbering into line. Nice.

Read more