Skip to main content

First OCR Spyware Breaches Both Apple and Google App Stores To Steal Crypto Wallet Phrases

3 months 1 week ago
Kaspersky researchers have discovered malware hiding in both Google Play and Apple's App Store that uses optical character recognition to steal cryptocurrency wallet recovery phrases from users' photo galleries. Dubbed "SparkCat" by security firm ESET, the malware was embedded in several messaging and food delivery apps, with the infected Google Play apps accumulating over 242,000 downloads combined. This marks the first known instance of such OCR-based spyware making it into Apple's App Store. The malware, active since March 2024, masquerades as an analytics SDK called "Spark" and leverages Google's ML Kit library to scan users' photos for wallet recovery phrases in multiple languages. It requests gallery access under the guise of allowing users to attach images to support chat messages. When granted access, it searches for specific keywords related to crypto wallets and uploads matching images to attacker-controlled servers. The researchers found both Android and iOS variants using similar techniques, with the iOS version being particularly notable as it circumvented Apple's typically stringent app review process. The malware's creators appear to be Chinese-speaking actors based on code comments and server error messages, though definitive attribution remains unclear.

Read more of this story at Slashdot.

msmash

Poland’s 2nd astronaut brings pierogi to the ISS party

3 months 1 week ago
Here's hoping freeze-dried Polish dumplings are just as good as ones freshly fried in butter

When Axiom Space's fourth mission to the International Space Station arrives in orbit this spring it'll include Poland's second-ever astronaut, who will bring an essential comfort from home: Pierogi.…

Brandon Vigliarolo

'I'm Done With Ubuntu'

3 months 1 week ago
Software developer and prolific blogger Herman Ounapuu, writing in a blog post: I liked Ubuntu. For a very long time, it was the sensible default option. Around 2016, I used the Ubuntu GNOME flavor, and after they ditched the Unity desktop environment, GNOME became the default option. I was really happy with it, both for work and personal computing needs. Estonian ID card software was also officially supported on Ubuntu, which made Ubuntu a good choice for family members. But then something changed. Ounapuu recounts how Ubuntu's bi-annual long-term support releases consistently broke functionality, from minor interface glitches to catastrophic system failures that left computers unresponsive. His breaking point came after multiple problematic upgrades affecting family members' computers, including one that rendered a laptop completely unusable during an upgrade from Ubuntu 20.04 to 22.04. Another incident left a relative's system with broken Firefox shortcuts and duplicate status bar icons after updating Lubuntu 18.04. Canonical's aggressive push of Snap packages has drawn particular criticism. The forced migration of system components from traditional Debian packages to Snaps resulted in compatibility issues, broken desktop shortcuts, and government ID card authentication failures. In one instance, he writes, a Snap-related bug in the GNOME desktop environment severely disrupted workplace productivity, requiring multiple system restarts to resolve. The author has since switched to Fedora, praising its implementation of Flatpak as a superior alternative to Snaps.

Read more of this story at Slashdot.

msmash

Nissan Set To Step Back From Merger With Honda

3 months 1 week ago
An anonymous reader shares a report: Nissan looks set to step back from merger talks with rival Honda, two sources said on Wednesday, calling into question a $60 billion tie-up to create the world's no.3 automaker and potentially leaving Nissan to drive its turnaround alone. Talks between the two Japanese automakers have been complicated by growing differences, according to multiple people familiar with the matter. Reuters reported earlier that Nissan could call off talks after Honda sounded it out about becoming a subsidiary. Nissan baulked as this was a departure from what was originally framed as a merger of equals, one of the people said.

Read more of this story at Slashdot.

msmash