JAKARTA - Kaspersky researchers managed to find a new Trojan spy named SparkKitty that targets iOS and Android phone users in Southeast Asia and China.

This Trojan works by posing as an app that looks legal, such as crypto apps, online gambling, or even TikTok, and is distributed through the App Store, Google Play, as well as fraudulent websites that resemble official app stores.

Once malicious apps are downloaded and installed, the app secretly infects the phone and runs in the background without collecting data by accessing the gallery and mobile system, and sending it to the attacker.

Experts argue that the attackers' goal is to steal crypto assets, and users in Indonesia also have the potential to pose a similar cyber threat risk.

Kaspersky has notified Google and Apple of the malicious app. The SparkKitty case is the second time in a year that Kaspersky researchers have found a Trojan Stealer on the App Store, after SparkCat.

iOS

On the App Store, the Trojan pretends to be an app related to crypto assets coins. On the phishing page that imitates the official iPhone App Store, the malware is distributed under the guise of TikTok and online gambling apps.

Android

While on Android, attackers target users on third-party websites and Google Play, by disguising malware as various crypto services.

"For example, one of the applications infected with a messenger application called SOEX with the crypto asset exchange function downloaded from the official store more than 10,000 times," Kaspersky wrote in his statement.

To avoid becoming a victim of this malware, Kaspersky recommends the following safety measures:

If the infected app has been installed, delete it immediately from the device and don't use it until the update is released to remove the malicious function

Avoid storing screenshots containing sensitive information in the gallery such as passwords

Use reliable cybersecurity software, to prevent malware infections

If an app asks permission to access the phone's photo library, consider if this app really needs it.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)