Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Screenshot-reading malware cracks iPhone security for the first time

Add as a preferred source on Google
A person holding an iPhone in their hand.
Bagus Hernawan / Unsplash

In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

Recommended Videos

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

An app listed on the App Store infected by malware.
Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

One of the iPhone apps infected by OCR malware.
Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.

Nadeem Sarwar
Nadeem is the Managing Editor at Digital Trends.
Google’s next Gemini upgrade might not arrive as soon as expected
Even Google's AI needs more time to finish its homework
google-gemini-ai-news-accuracy

Google helped kickstart the modern AI race, but staying ahead has turned out to be far more difficult than joining it. According to a new Bloomberg report, the company has fallen months behind its internal schedule for launching Gemini 3.5 Pro, its next flagship AI model, as engineers continue working to improve one of its biggest weaknesses: coding.

The delay isn't simply about polishing another chatbot. It highlights a broader problem facing Google, where massive engineering teams, multiple product divisions and increasingly strict AI safety requirements are slowing the company's ability to respond to rivals that seem happy to move much faster.

Read more
The iPhone 18 Pro Max camera could open and close like a real lens for better portraits
A leaked factory log just spoiled the iPhone 18 Pro Max’s best camera upgrade
iphone 18 pro

Apple’s next flagship camera may learn how to open and close its eye. A diagnostic log reportedly connected to the iPhone 18 Pro Max contains calibration data for a variable-aperture main camera, according to Notebookcheck.

The internal document was found among files allegedly stolen from Apple supplier Tata Electronics and released by the World Leaks ransomware group. Apple has neither verified the material nor commented on the report. And of course, Apple has neither verified the material nor commented on the report.

Read more
Messi or Ronaldo? Caviar made football’s greatest rivalry an expensive 24-karat choice
Football’s biggest debate just became Android vs iPhone
Samsung Galaxy Z Fold 8 Ultra and iPhone 17 Pro with 24-karat gold design with Ronaldo and Messi etching

Caviar has moved football’s greatest debate onto another fiercely contested battlefield. The Android versus iPhone discussion is getting more heated by adding Ronaldo and Messi to the mix. The luxury-device company's new Legends collection pairs Lionel Messi with a customized Samsung Galaxy Z Fold 8 Ultra, while Cristiano Ronaldo gets an iPhone 17 Pro and iPhone 17 Pro Max. Both designs use handcrafted cloisonné enamel and 24-karat gold plating, with prices starting at $18,382 for Messi’s foldable and $15,974 for Ronaldo’s iPhone.

Messi gets the foldable, Ronaldo gets the iPhone

Read more