Skip to main content

Screenshot-reading malware cracks iPhone security for the first time

A person holding an iPhone in their hand.
Bagus Hernawan / Unsplash

In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

Recommended Videos

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

An app listed on the App Store infected by malware.
Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.

Please enable Javascript to view this content

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

One of the iPhone apps infected by OCR malware.
Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.

Nadeem Sarwar
Nadeem is a tech and science journalist who started reading about cool smartphone tech out of curiosity and soon started…
Oppo’s next phone has an iPhone 16 Pro-beating feature
Close up of the Find X8 Pro camera on a colorful background

Oppo's compact flagship phone is close to launching, is confirmed to be called the Oppo Find X8s. The company has been teasing its advancements over the competition fervently and recently threw light on the phone's display upgrades over other phones, including one way it beats the iPhone 16 Pro.

The Oppo Find X8s is claimed to feature extremely thin bezels along all four sides of its display. Zhou Yibao, the product manager for Oppo's flagship Find series, shared an image on Chinese social media Weibo comparing the bezels on the upcoming compact phone -- previously speculated to be called the Find X8 Mini -- with those on what appears to be an iPhone 16 Pro or the iPhone 16 Pro Max.

Read more
iPhone 17 Air might not serve a price shock, after all
Alleged concept render of the iPhone 17 Air in black.

Ever since we first heard murmurs of Apple prepping an ultra-slim iPhone, speculations were rife about a fittingly high asking price. But it seems buyers won’t get hit with an absurd “innovation tax” for the iPhone 17 Air model later this year.
According to Bloomberg, the upcoming phone might be priced at “roughly $900.” To put that into perspective, that’s the same asking price as the iPhone 16 Plus. To recall, the iPhone 17 Air is expected to replace the “Plus” model in Apple’s line-up later this year.

A few pleasant surprises
The package, however, is going to be a mixed bag of surprises. For example, the slim phone is expected to offer a 6.6-inch display, but it will borrow the ProMotion display tech from the pricier Pro models. So far, the high refresh rate perk has been exclusive to Apple’s flagship iPhones and iPads.

Read more
We just got our best look yet at the iPhone 17 Air
Face ID on the iPhone 16e

As the release for the iPhone 17 draws ever closer (expected in September 2025), more leaks have emerged — and now a set of dummy units give us a close look at the entire lineup, but specifically the iPhone 17 Air. This handset has been the source of quite a bit of speculation and rumors, and a peek at its profile shows a phone even slimmer than we had imagined.

The leaks come courtesy of Sonny Dickson, a well-known tipster. Dickson shared the images on X. It's important to remember that these units are chunks of metal; they have no electronics inside them, so we can't gauge specs based on the design. It does give us a firm look at the profile, however, and an idea of the placement of various components.

Read more