Connect with us

News

Password & Crypto-Stealing Trojan Targets UAE Users Via App Stores

The newly-discovered malware, named SparkCat, uses optical recognition to scan for sensitive data inside screenshots and photos.

Published

on

password and crypto stealing trojan targets uae users via app stores

Researchers at Kaspersky have identified a Trojan lurking in both the App Store and Google Play since at least March 2024. The malware is known as SparkCat, and it uses optical recognition to scan image galleries, stealing sensitive data like crypto wallet recovery phrases and passwords from user’s screenshots and photos.

How SparkCat Spreads

The malware is being distributed through both infected legitimate apps and cleverly disguised lures. These include messaging apps, AI assistants, food delivery services, and crypto-related applications. Some of the compromised apps have made their way into Google Play and the App Store, while others are circulating through unofficial sources.

Who’s At Risk?

Worryingly for our readers, the primary targets appear to be users in the United Arab Emirates. However, various countries in Europe and Asia have also been targeted, as SparkCat’s optical scanning can detect multiple languages.

How It Works

Once installed, SparkCat may request permission to access a user’s photo gallery. From there, it uses an optical character recognition (OCR) module to scan stored images for relevant keywords. If it detects sensitive data — particularly screenshots of recovery phrases for cryptocurrency wallets — it transmits the images to attackers. With this information, hackers can gain full access to a victim’s funds.

Who’s Behind It?

An analysis of the Android version of SparkCat revealed code comments written in Chinese, while the iOS variant included home directory names like qiongwu and quiwengjing. While these clues suggest a Chinese-speaking threat actor, there isn’t enough evidence to link the software to any known cybercriminal groups.

Sergey Puzan, a malware analyst at Kaspersky, noted, “This is the first known case of OCR-based Trojan to sneak into AppStore. In terms of both AppStore and Google Play, at the moment it’s unclear whether applications in these stores were compromised through a supply chain attack or through various other methods. Some apps, like food delivery services, appear legitimate, while others are clearly designed as lures”.

How To Protect Yourself

To minimize the risk of infection, Kaspersky recommends taking the following precautions:

  • If you’ve installed an affected app, delete it immediately and avoid using it until a safe update is available.
  • Avoid saving screenshots that contain sensitive information, such as crypto wallet recovery phrases. Instead, use secure password managers.
  • Consider using reputable cybersecurity solutions like Kaspersky Premium to safeguard against malware threats.

As and mobile malware tactics evolve, staying cautious with app downloads and maintaining strong security practices can go a long way in keeping your data safe.

Advertisement

📢 Get Exclusive Monthly Articles, Updates & Tech Tips Right In Your Inbox!

JOIN 23K+ SUBSCRIBERS

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Visa’s Return To Syria Starts With A Test And A Bank In Lebanon

Foreign visitors will be the first users to benefit, but whether Syria’s own banks and cardholders follow is still an open question.

Published

on

visa's return to syria starts with a test and a bank in lebanon

Visa is returning to Syria. Its first live international card transaction in the country was a test rather than a launch, and the milestone event ran through a Lebanese bank.

The acquirer (the bank on the merchant’s side of a card payment) was Fransabank Lebanon, with Paymera as the other named partner. Nadim Moujaes, who heads a Fransabank Group subsidiary, describes the test as both the culmination of “longstanding efforts to link Syria back to international payment networks” and “the first step in a larger path”.

“We are excited to have successfully tested live transactions today as we plan to enable international visitors to use their Visa cards while in Syria,” says Leila Serhan, Visa’s senior vice president and group country manager for the North Africa, Levant and Pakistan region. Although a significant first step, that plan doesn’t come with a hard date for when a visitor’s card will work normally.

Mohammed Safwat Raslan, governor of the Central Bank of Syria, says the test paves the way for international card acceptance in Syria and that maintaining strong compliance, risk management and operational controls will remain essential. Serhan likewise stresses that Visa has worked within applicable legal, regulatory and compliance requirements. For a test transaction, it seems there was a great deal of attention paid to the rules, with the entire operation being carefully managed.

Also Read: Lebanon’s 5G Era Begins With 150 Stations And A $1M Budget

The test is the latest step in a sequence that began in December 2025, when Visa announced a strategic roadmap to support Syria’s integration into the global digital economy. In February 2026 it hosted its first industry gathering of banks, ecosystem partners and policymakers in Damascus and, the same month, signed an agreement with Syria’s Ministry of Communications and Information Technology in San Francisco.

Michel Kattouah, Paymera’s CEO, called the test “the return of international card acceptance,” but while that’s positive news, there’s no word yet on when a Syrian bank will issue a Visa card to a Syrian customer.

Continue Reading

#Trending