Cyber999 Advisories

14 February 2025     Advisory

MA-1260.022025: MyCERT Advisory - SparkCat Malware Infiltrates Apps on Google Play and Apple App Store


1.0 Introduction
The Cyber999 Incident Response Centre has recently been alerted to a new cybersecurity threat identified by Kaspersky, known as SparkCat. This malware has infiltrated both the Google Play Store and Apple App Store, posing a serious risk to mobile users in Malaysia. SparkCat is designed to steal sensitive information using Optical Character Recognition (OCR) technology, enabling it to extract credentials, financial details, and cryptocurrency wallet information from screenshots and text input.

2.0 Impact
The SparkCat given its ability to bypass official app store security measures, which can cause significant risk of data breaches, financial fraud, and unauthorised access to user accounts.

3.0 Affected System
Android & IOS

4.0 Indicators of Compromise
4.1 Infected Android apps


4.2 iOS framework MD5s:


4.3 Trojan configuration in GitLab


4.4 C2


4.5 Photo storage


4.6 Infected Android APKs from Google Play

  • com.crownplay.vanity.address
  • com.atvnewsonline.app
  • com.bintiger.mall.android
  • com.websea.exchange
  • org.safew.messenger
  • org.safew.messenger.store
  • com.tonghui.paybank
  • com.bs.feifubao
  • com.sapp.chatai
  • com.sapp.starcoin


4.7 BundleIDs encrypted inside the iOS frameworks

  • im.pop.app.iOS.Messenger
  • com.hkatv.ios
  • com.atvnewsonline.app
  • io.zorixchange
  • com.yykc.vpnjsq
  • com.llyy.au
  • com.star.har91vnlive
  • com.jhgj.jinhulalaab
  • com.qingwa.qingwa888lalaaa
  • com.blockchain.uttool
  • com.wukongwaimai.client
  • com.unicornsoft.unicornhttpsforios
  • staffs.mil.CoinPark
  • com.lc.btdj
  • com.baijia.waimai
  • com.ctc.jirepaidui
  • com.ai.gbet
  • app.nicegram
  • com.blockchain.ogiut
  • com.blockchain.98ut
  • com.dream.towncn
  • com.mjb.Hardwood.Test
  • com.galaxy666888.ios
  • njiujiu.vpntest
  • com.qqt.jykj
  • com.ai.sport
  • com.feidu.pay
  • app.ikun277.test
  • com.usdtone.usdtoneApp2
  • com.cgapp2.wallet0
  • com.bbydqb
  • com.yz.Byteswap.native
  • jiujiu.vpntest
  • com.wetink.chat
  • com.websea.exchange
  • com.customize.authenticator
  • im.token.app
  • com.mjb.WorldMiner.new
  • com.kh-super.ios.superapp
  • com.thedgptai.event
  • com.yz.Eternal.new
  • xyz.starohm.chat
  • com.crownplay.luckyaddress1


5.0 Recommendations
CyberSecurity Malaysia advises users to follow the steps given below to protect themselves from becoming victims.

  • Immediately uninstall any SparkCat infected applications from your device as they steal sensitive data, including cryptocurrency wallet information, using OCR technology.
  • Regularly review and limit app permissions, especially for access to camera, storage, or clipboard, and revoke unnecessary access to sensitive data like passwords or wallet information.
  • Install reputable mobile security solutions that can detect and block malicious apps like SparkCat, offering real-time protection against emerging threats.
  • Enable two-factor authentication (2FA) to provide an extra layer of protection for all accounts involving sensitive or financial data
  • Regularly monitor your financial and crypto accounts for unauthorized transactions and report any suspicious activity to the relevant authorities or service provider immediately.
  • Ensure that both your device’s operating system and apps are kept up to date with the latest security patches.
  • Avoid downloading apps from unofficial sources and stick to trusted platforms like Google Play Store and Apple App Store, while remaining cautious as official stores can still host malicious apps.
  • Regularly backup important data, especially financial and crypto assets, using secure cloud services or offline storage methods.

For further enquiries, please contact us through the following channels:

E-mail: cyber999[at]cybersecurity.my 
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting) 
Business Hours: Mon - Fri 08:30 -17:30 MYT 
Web:  https://www.mycert.org.my  

6.0 References

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed