#SpyAgent

Olly 👾Olly42@nerdculture.de
2024-09-10

SpyAgent Android Malware steals your Crypto Recovery Phrases from Images. :androidalt:

A new Android malware named SpyAgent uses optical character recognition (OCR) technology to steal cryptocurrency wallet recovery phrases from screenshots stored on the mobile device.

mcafee.com/blogs/other-blogs/m

#android #spyagent #malware #it #security #privacy #technology #engineering #tech #media #news

A malware operation discovered by McAfee was traced back to at least 280 APKs distributed outside of Google Play using SMS or malicious social media posts. This malware can use OCR to recover cryptocurrency recovery phrases from images stored on an Android device, making it a significant threat.[ImageSource: McAfee]

Code that performs the OCR scanning of images.

The stolen images are processed and OCR-scanned on the server side and then organized on the admin panel accordingly to allow easy management and immediate utilization in wallet hijack attacks.

<To mitigate this risk on Android, it is important not to install Android apps outside of Google Play, as they are commonly used to distribute malware.>[ImageSource: McAfee]

Some of the Android applications pretend to be for South Korean and UK government services, dating sites and pornography sites.

Though the activity mainly targeted South Korea, McAfee has observed a tentative expansion to the UK and signs that an iOS variant might be in early development.
Scripter :verified_flashing:scripter@social.tchncs.de
2024-09-09

Android-Malware: SpyAgent stiehlt Zugangsdaten zu Krypto-Wallets | heise online
heise.de/-9861205 #Cybercrime #Android #Malware #SpyAgent #Zugangsdaten #OCR

Renaud Lifchitz :verified:nono2357@infosec.exchange
2024-09-07
gtbarrygtbarry
2024-07-31

Another major spyware firm has been breached — thousands of devices have private details exposed

A US spyware maker called Spytech has been breached, leading to sensitive data it held on thousands of its victims being leaked online.

Spytech operates two spyware apps - Realtime-Spy and SpyAgent.

techradar.com/pro/security/ano

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst