Cyber Security

New Android Malware SpyAgent Taking Screenshots Of Users’ Devices

Android malware has evolved significantly since its inception, transitioning from simple threats like SMS Trojans to complex ransomware and banking Trojans.

The evolution of Android malware reflects a broader trend of increasing sophistication in mobile malware driven by the Android ecosystem’s open nature.

Security Intelligence researchers recently discovered a new Android malware dubbed “SpyAgent” that takes screenshots of users’ devices.

A new Android malware strain, SpyAgent, is now targeting screenshots of cryptocurrency recovery phrases stored on devices using OCR technology.

Attend a Free Webinar on How to Maximize Cybersecurity Program ROI

SpyAgent Taking Screenshots

The SpyAgent malware spreads via phishing, encouraging users to install malware-laden applications. After installation, the spy agent looks for screenshots containing the 12-24-word recovery phrases used in these wallets’ passwords.

Since these long phrases are certainly difficult to remember, many users take screenshots for reference, which makes them vulnerable to theft.

If the threat actors access these recovery phrases, they can use them to recover the associated cryptocurrency wallets and transfer the funds to their own accounts, reads the SecurityIntelligence report.

Once this is done, the stolen funds cannot be recovered as the crypto transactions are non-recoverable. This malware has spread mainly in Korea, affecting over 280 malicious APK files that were distributed externally to the official Google Play market.

There are also signs that SpyAgent may be looking to broaden its base and target users situated in the UK.

In addition to cryptocurrency, the potential of the malware’s ability to capture screenshots would also create dangers over any critical data that the users had screenshots like “business logins,” “personal identity,” and “contact details,” which would facilitate even more data leaks and instances of identity theft.

Screenshots containing critical and sensitive data are prime targets for malicious actors. To mitigate this threat, avoid taking screenshots altogether, be careful about unsolicited text messages, and only install applications from trusted sources.

However, perfect security is a myth, as no amount of precaution is ever enough with all these interconnected devices.

Industry data shows that organizations that use sophisticated security solutions are able to detect and mitigate breaches 100 days faster than the global average.

Recommendations

Here below we have mentioned all the recommendations:-

  • Make sure to maintain a measured approach to data storage.
  • Always analyze app sources.
  • Implement robust security solutions.
  • Invest in security automation and analytics.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago