McAfee has discovered a new Android malware called SpyAgent that can steal private keys stored in screenshots and photos on smartphones.
The software uses Optical Character Recognition (OCR) technology to scan and extract text from images, a feature that is commonly used across many platforms, including desktops.
McAfee Labs outlined how SpyAgent spreads through malicious links sent via text messages. Once the user clicks on the link, they are redirected to a fake but convincing website that prompts them to download a seemingly legitimate application. However, the app in question contains software that compromises the user’s phone upon installation.
The malware, masquerading as banking apps, government services and streaming platforms, requests permissions for contacts, messages and local storage. McAfee has detected SpyAgent in more than 280 apps targeting mostly South Korean users.
In August, a similar threat called “Cthulhu Stealer” was identified affecting macOS. Like SpyAgent, it masquerades as legitimate software and steals sensitive information such as MetaMask passwords and private keys for cold storage wallets.
Around the same time, Microsoft discovered a vulnerability in Google Chrome that is likely being exploited by a North Korean hacking group known as Citrine Sleet. This group creates fake crypto exchanges to lure victims with fake job applications that install malware to steal private keys. Although the Chrome vulnerability has been patched, the rise in the number of such attacks has prompted the FBI to issue a warning about Citrine Sleet’s activities.
Alex Mashinsky, the former CEO of Celsius serving a 100-year prison sentence, is seeking the testimony of six ex-employees as part of his criminal case.
Since Bitcoin’s inception in 2009, it initially struggled to gain recognition as a groundbreaking technology, often being dismissed as a scam or fraud.
Former Binance CEO Changpen Zhao is nearing the end of his four-month prison sentence, with his release scheduled for September 29, according to the US Federal Bureau of Prisons.
The notorious hacking group known for its crypto thefts has lost access to nearly $5 million in stablecoins, following actions taken by stablecoin issuers to freeze the funds.