Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » New Android malware SpyAgent uses OCR to steal crypto wallet recovery keys
Global Security

New Android malware SpyAgent uses OCR to steal crypto wallet recovery keys

AdminBy AdminSeptember 9, 2024No Comments3 Mins Read
Android SpyAgent Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 9, 2024Ravi LakshmananMobile Security / Cryptocurrency

SpyAgent Android Malware

Android device users in South Korea have been targeted by a new mobile malware campaign that introduces a new type of threat called SpyAgent.

The malware “targets mnemonic keys by scanning images on your device that may contain them,” said McAfee Labs researcher SangRyol Ryu said in the analysis, the addition of the target footprint expanded the scope to include the UK

The company uses fake Android apps that masquerade as seemingly legitimate banking, government, streaming apps, and utilities to trick users into installing them. Since the beginning of the year, 280 fake applications have been detected.

It all starts with SMS messages containing links to landmines that encourage users to download the apps in question as APK files hosted on fraudulent websites. Once installed, they are designed to request intrusive permissions to collect data from devices.

Cyber ​​security

This includes contacts, SMS messages, photos and other information about the device, which is then transmitted to an external server under the control of the threat.

SpyAgent malware

The most notable feature is its ability to use optical character recognition (OCR) to steal mnemonic keys related to the recovery phrase or seed phrase that allows users to regain access to their cryptocurrency wallets.

Therefore, unauthorized access to mnemonic keys can allow threat actors to take control of victims’ wallets and extract all funds stored in them.

McAfee Labs said the Command and Control (C2) infrastructure suffered from serious security flaws that not only allowed access to the site’s root directory without authentication, but also left exposed data collected by victims.

The server also hosts an admin panel that acts as a one-stop shop for remote management of infected devices. The presence on the dashboard of an Apple iPhone running iOS 15.8.2 with the system language set to Simplified Chinese (“zh”) is a sign that it may also be targeting iOS users.

SpyAgent malware

“Initially, the malware communicated with its command and control (C2) server through simple HTTP requests,” Ryu said. “While this method was effective, it was also relatively easy for the security tool to track and block.”

“In a significant tactical shift, the malware has now adopted WebSocket connections for its communication. This update enables more efficient two-way real-time interaction with the C2 server and helps it avoid detection by traditional HTTP-based network monitoring tools. .”

Cyber ​​security

The development comes just over a month after Group-IB exposed another Android Remote Access Trojan (RAT) called CraxsRAT has been targeting banking users in Malaysia since at least February 2024 via phishing websites. It should be noted that CraxsRAT campaigns were also previously discovered to have targeted Singapore by April 2023 at the latest.

“CraxsRAT is a known Android Remote Administration Tools (RAT) malware family that provides remote device control and spyware capabilities, including keylogging, gesture tracking, camera, screen and call recording,” the Singapore-based company said. said.

“Victims who downloaded apps containing the CraxsRAT Android malware will experience credential leaks and illegitimate withdrawals.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.