McAfee has discovered a new Android malware called SpyAgent that can steal private keys stored in screenshots and photos on smartphones.
The software uses Optical Character Recognition (OCR) technology to scan and extract text from images, a feature that is commonly used across many platforms, including desktops.
McAfee Labs outlined how SpyAgent spreads through malicious links sent via text messages. Once the user clicks on the link, they are redirected to a fake but convincing website that prompts them to download a seemingly legitimate application. However, the app in question contains software that compromises the user’s phone upon installation.
The malware, masquerading as banking apps, government services and streaming platforms, requests permissions for contacts, messages and local storage. McAfee has detected SpyAgent in more than 280 apps targeting mostly South Korean users.
In August, a similar threat called “Cthulhu Stealer” was identified affecting macOS. Like SpyAgent, it masquerades as legitimate software and steals sensitive information such as MetaMask passwords and private keys for cold storage wallets.
Around the same time, Microsoft discovered a vulnerability in Google Chrome that is likely being exploited by a North Korean hacking group known as Citrine Sleet. This group creates fake crypto exchanges to lure victims with fake job applications that install malware to steal private keys. Although the Chrome vulnerability has been patched, the rise in the number of such attacks has prompted the FBI to issue a warning about Citrine Sleet’s activities.
On October 4, 2024, the U.S. government took legal steps to recover over $2.67 million in digital assets that were allegedly pilfered by North Korea’s Lazarus Group.
A recent alert from a U.S. government agency highlights the growing threat of Trinity ransomware, notorious for demanding cryptocurrency payments from victims while threatening to disclose sensitive information.
Binance, the world’s largest cryptocurrency exchange, has rejected 86% of Israeli military requests to freeze crypto wallets linked to Palestinians and others due to a lack of sufficient evidence.
Binance’s latest insights reveal a substantial drop in digital asset losses due to hacks in 2024, marking a notable shift in the industry’s security landscape.