Connect with us

Technology

Screenshot-scanning malware discovered on Apple App Store in first-of-its-kind attack

Published

on

Screenshot-scanning malware discovered on Apple App Store in first-of-its-kind attack

Every tech expert will tell you the App Store is safer than Google Play Store. Some might even claim it is impossible to download a malicious app from the App Store, but they are wrong. 

While I admit the App Store is a secure and tightly controlled ecosystem, it cannot completely shield you. Security researchers have found that hackers are targeting several apps on the App Store to spread malware that steals information from screenshots saved on a device. 

The issue also affects those downloading apps from the Google Play Store.

STAY PROTECTED & INFORMED! GET SECURITY ALERTS & EXPERT TECH TIPS — SIGN UP FOR KURT’S THE CYBERGUY REPORT NOW

A person holding an iPhone. (Kurt “CyberGuy” Knutsson )

Advertisement

How the malware works and what makes it different

According to researchers at Kaspersky, this malware campaign is more advanced than typical info stealers, both in how it works and how it spreads. Instead of relying on social engineering tricks to get users to grant permissions like most banking trojans or spyware, this malware hides inside seemingly legitimate apps and slips past Apple and Google’s security checks.

One of its standout features is Optical Character Recognition. Instead of stealing stored files, it scans screenshots saved on the device, extracts text and sends the information to remote servers.

Once installed, the malware operates stealthily, often activating only after a period of dormancy to avoid raising suspicion. It employs encrypted communication channels to send stolen data back to its operators, making it difficult to trace. Plus, it spreads through deceptive updates or hidden code within app dependencies, an approach that helps it evade initial security screenings by app store review teams.

The infection vectors vary between Apple and Google’s ecosystems. On iOS, the malware is often embedded within apps that initially pass Apple’s rigorous review process but later introduce harmful functionality through updates. On Android, the malware can exploit sideloading options, but even official Google Play apps have been found to carry these malicious payloads, sometimes hidden within SDKs (software development kits) supplied by third-party developers.

Messaging app

Messaging app in the App Store designed to lure victims.

THE HIDDEN COSTS OF FREE APPS: YOUR PERSONAL INFORMATION

Advertisement

What’s being stolen, and who’s responsible?

The scope of stolen information is alarming. This malware primarily targets crypto wallet recovery phrases but is also capable of exfiltrating login credentials, payment details, personal messages, location data and even biometric identifiers. Some versions are designed to harvest authentication tokens, allowing attackers to access accounts even if users change their passwords.

The apps serving as malware carriers include ComeCome, ChatAi, WeTink, AnyGPT and more. These range from productivity tools to entertainment and utility apps. In some cases, malicious developers create these apps with full knowledge of the malware’s purpose. In others, the issue appears to be a supply chain vulnerability, where legitimate developers unknowingly integrate compromised SDKs or third-party services that introduce malicious code into their applications.

We reached out to Apple for a comment but did not hear back before our deadline. 

App Store

Messaging app in the App Store designed to lure victims. (Kaspersky)

Apple’s response to screenshot-scanning malware discovered in App Store

Apple has removed the 11 iOS apps mentioned in Kaspersky’s report from the App Store. Furthermore, they discovered that these 11 apps shared code signatures with 89 other iOS apps, all of which had been previously rejected or removed for violating Apple’s policies, resulting in the termination of their developer accounts.

Apps requesting access to user data such as Photos, Camera or Location must provide relevant functionality or face rejection. They must also clearly explain their data usage when prompting users for permission. iOS privacy features ensure users always control whether their location information is shared with an app. Also, starting in iOS 14, the PhotoKit API — which allows apps to request access to a user’s Photos library — added additional controls to let users select only specific photos or videos to share with an app instead of providing access to their entire library. 

Advertisement

The App Store Review Guidelines mandate that developers are responsible for ensuring their entire app, including ad networks, analytics services and third-party SDKs, complies with the guidelines. Developers must carefully review and choose these components. Apps must also accurately represent their privacy practices, including those of the SDKs they use, in their privacy labels.

In 2023, the App Store rejected over 1.7 million app submissions for failing to meet its stringent privacy, security and content standards. It also rejected 248,000 app submissions found to be spam, copycats or misleading and prevented 84,000 potentially fraudulent apps from reaching users.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

What Google is doing to stop malware 

A Google spokesperson tells CyberGuy: 

“All of the identified apps have been removed from Google Play and the developers have been banned. Android users are automatically protected from known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services.”

Advertisement

However, it is important to note that Google Play Protect may not be enough. Historically, it isn’t 100% foolproof at removing all known malware from Android devices. Here’s why:

What Google Play Protect can do:

  • Scans apps from the Google Play Store for known threats.
  • Warns you if an app behaves suspiciously.
  • Detects apps from unverified sources (sideloaded APKs).
  • Can disable or remove harmful apps.

What Google Play Protect can’t do:

  • It does not provide real-time protection against advanced threats like spyware, ransomware or phishing attacks.
  • It does not scan files, downloads or links outside of Play Store apps.
  • It may miss malware from third-party app stores or sideloaded apps.
  • It lacks features like VPN protection, anti-theft tools and privacy monitoring.
password

Image of a person typing in their password on screen. (Kurt “CyberGuy” Knutsson)

HOW SCAMMERS USE YOUR PERSONAL DATA FOR FINANCIAL SCAMS AND HOW TO STOP THEM

5 ways users can protect themselves from such malware

1. Use strong antivirus software: Installing strong antivirus software can add an extra layer of protection by scanning apps for malware, blocking suspicious activity and alerting you to potential threats. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

2. Stick to trusted developers and well-known apps: Even though malware has been found in official app stores, users can still minimize their risk by downloading apps from reputable developers with a long track record. Before installing an app, check its developer history, read multiple reviews and look at the permissions it requests. If an app from an unknown developer suddenly gains popularity but lacks a strong review history, approach it with caution.

Advertisement

3. Review app permissions carefully: Many malicious apps disguise themselves as legitimate tools but request excessive permissions that go beyond their stated purpose. For example, a simple calculator app should not need access to your contacts, messages or location. If an app asks for permissions that seem unnecessary, consider it a red flag and either deny those permissions or avoid installing the app altogether. Go to your phone settings and check app permissions on your iPhone and Android

4. Keep your device and apps updated: Cybercriminals exploit vulnerabilities in outdated software to distribute malware. Always keep your operating system and apps updated to the latest versions, as these updates often contain critical security patches. Enabling automatic updates ensures that you stay protected without having to manually check for new versions.

5. Be wary of apps that promise too much: Many malware-infected apps lure users by offering features that seem too good to be true — such as free premium services, extreme battery optimizations or AI-powered functionality that appears unrealistic. If an app’s claims sound exaggerated or its download numbers skyrocket overnight with questionable reviews, it’s best to avoid it. Stick to apps with a transparent development team and verifiable functionalities. 

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET 

Kurt’s key takeaway

The new malware campaign highlights the need for stricter vetting processes, continuous monitoring of app behavior post-approval and greater transparency from app stores regarding security risks. While Apple and Google have removed the malicious apps upon detection, the fact that they made it onto the platform in the first place exposes a gap in the existing security framework. As cybercriminals refine their methods, app stores must evolve just as quickly or risk losing the trust of the very users they claim to protect.

Advertisement

Do you think app stores should take more responsibility for malware slipping through? Let us know by writing us at Cyberguy.com/Contact

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Samsung soundbar owners report major problems after latest firmware update

Published

on

Samsung soundbar owners report major problems after latest firmware update

Samsung’s flagship soundbar, the HW-Q990D, is being rendered useless for some owners after a faulty firmware update that the company rolled out this week. The sheer number of reports on Samsung’s community forums, Reddit, and AVSForum confirm that something has gone very wrong with the premium Dolby Atmos system in recent days. The issue isn’t limited to any specific region, with customers in the United States, Austria, the Philippines, Malaysia, and other countries all sharing in the frustration.

Customers say the soundbar has gone unresponsive and that none of the usual factory reset methods are working; affected units are also inaccessible via Samsung’s SmartThings app. The device powers on, but appears to freeze on the TV eARC input — with no sound output to speak of.

The culprit seems to be the latest firmware release, which is version 1020.7. Many Q990Ds are set to automatically install new updates, which has led to widespread complaints about the bad software over the last several days. If you’ve got a Samsung soundbar, it might be wise to disable automatic updates for the time being until this situation has cleared up. There are scattered reports of the same bug impacting other Samsung models like the HW-Q800D and HW-S801D, but the bulk of complaints pertain to the Q990D. It’s one of the most well-reviewed soundbars on the market, so this is an unfortunate development.

The Verge has reached out to Samsung for comment. Apparently some customers have already been instructed to send in their Q990D hardware for repair. That seems like a worst case scenario, so hopefully Samsung will have an easier, at-home solution once it realizes the scope of this problem. Can the malfunction be resolved with another firmware update in the coming days? Stay tuned.

Thanks for the tip, Eric.

Advertisement
Continue Reading

Technology

Solar-powered roof wraps new mega-modern opera house

Published

on

Solar-powered roof wraps new mega-modern opera house

In the heart of Priština, the capital of Kosovo, a small country in Southeast Europe, an architectural and cultural revolution is underway. 

The Kosovo Opera and Ballet Theatre, recently unveiled, promises to become a landmark not just for the city but for the entire region. 

As the first opera house in Kosovo, this project represents a monumental step forward for a nation that has been steadily building its cultural identity since gaining independence in 2008. 

Combining cutting-edge technology, sustainable design and a deep connection to local traditions, the theater is poised to captivate audiences from around the world.

STAY SAFE & IN THE KNOW — AT NO COST! SUBSCRIBE TO KURT’S THE CYBERGUY REPORT FOR FREE SECURITY ALERTS & TECH TIPS

Advertisement

The Kosovo Opera and Ballet Theatre (Bjarke Ingels Group)

A solar-powered symbol of tradition

The theater’s most eye-catching feature is its flowing, undulating roof, which spans an impressive area and is entirely clad in solar panels. These photovoltaic panels are designed to generate renewable energy on-site, significantly reducing the building’s environmental impact while also lowering its operational costs. 

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

The roof’s design is more than just functional; it takes inspiration from the xhubleta, a traditional bell-shaped skirt worn by women in Kosovo. This cultural reference transforms the structure into a modern symbol of national pride while creating an exterior that is both elegant and dynamic. The roof’s soft curves intuitively guide visitors toward key entrances and spaces, making navigation seamless and inviting from every angle.

solar roof 2

The Kosovo Opera and Ballet Theatre (Bjarke Ingels Group)

5 BEST PORTABLE CHARGERS FOR ANY OCCASION

Advertisement

Architecture that balances beauty and functionality

Inside, the theater is designed to deliver an unparalleled experience for performers and audiences alike. The central foyer, illuminated by a massive skylight, serves as a welcoming hub that connects all four performance spaces. These include a 1,200-seat Concert Hall, a 1,000-seat Theatre Hall, a 300-seat Recital Hall and a flexible Theatre Room. Each space is crafted with meticulous attention to acoustics and sightlines to ensure every performance feels intimate and immersive.

The interior design features curved wooden elements that not only add sculptural beauty but also enhance sound quality throughout the venue. The use of natural materials like timber creates a warm and cohesive atmosphere, while deep velvet upholstery and acoustic curtains add both comfort and functionality.

solar roof 3

The Kosovo Opera and Ballet Theatre (Bjarke Ingels Group)

A BIRDHOUSE-INSPIRED TINY HOUSE NESTLED IN NATURE THAT RUNS ON SOLAR POWER 

Connecting culture with community

The theater does not stand alone; it has been carefully integrated into its urban surroundings to serve as both a cultural hub and a public gathering space. Located near major landmarks like the Palace of Youth and Sports and Fadil Vokrri Stadium, the building sits at the heart of Priština’s emerging cultural district. A large public staircase connects the theater directly to Garibaldi Street, improving pedestrian access while creating an inviting plaza where locals and visitors can gather. The existing podium of the nearby Palace of Youth has been extended to merge with the theater’s base, further enhancing connectivity and activating the area as a vibrant public space.

Advertisement

The surrounding landscape has been thoughtfully designed to complement the building’s architecture while promoting biodiversity. Natural stone paving is interspersed with planted islands featuring beech trees and other vegetation native to the region. These green spaces provide shade during warmer months while adding seasonal variety to the environment.

MALWARE STEALS BANK CARDS AND PASSWORDS FROM MILLIONS OF DEVICES

solar roof 4

DON’T JUDGE THIS SOLAR CAR JUST BY ITS SIZE

A collaborative vision

The Kosovo Opera and Ballet Theatre is a collaborative effort between some of Europe’s most innovative designers. Bjarke Ingels Group, an internationally renowned architecture firm based in Denmark, partnered with ALB-Architect to bring this vision to life. Commissioned by Kosovo’s Ministry of Culture, Youth, and Sport, the project reflects a shared commitment to creating a space that meets both artistic and community needs. Bjarke Ingels himself described the theater as “an efficient factory for artistic performances,” emphasizing its adaptability and functionality alongside its striking visual appeal.

SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES

Advertisement
solar roof 5

The Kosovo Opera and Ballet Theatre (Bjarke Ingels Group)

Kurt’s key takeaways

The Kosovo Opera and Ballet Theatre is truly a remarkable blend of modern technology and sustainable practices, all while paying homage to local traditions. With its stunning solar-powered roof and inviting spaces designed for artistic excellence and community engagement, this theater is set to shine as a beacon of innovation in Southeast Europe and beyond. As Kosovo carves out its place on the international cultural map, this landmark is sure to play a vital role in shaping the future narrative of the nation.

Could integrating solar technology into iconic buildings, like this opera house, change how we view renewable energy in the U.S., or is it just architectural eye candy? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Advertisement

Follow Kurt on his social channels:

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading

Technology

Watch NASA’s SpaceX Crew-10 mission launch

Published

on

Watch NASA’s SpaceX Crew-10 mission launch

NASA’s SpaceX Crew-10 mission was originally scheduled for Wednesday evening from Kennedy Space Center’s Launch Complex 39A, before NASA and SpaceX scrubbed the attempt “due to a hydraulic system issue with a ground support clamp arm.”

Now that has been addressed and the launch date has been rescheduled to Friday, March 14th at 7:03PM ET, with a backup opportunity on Saturday at 6:41PM ET.

Once its there, NASA astronauts Butch Wilmore and Suni Williams will finally get a safe ride back home to Earth after being stranded aboard the ISS for nine months. Their Boeing Starliner mission that launched to the ISS on June 5th, 2024, was only supposed to last eight days, but issues like thruster failures and helium leaks made it unsafe to return to Earth using Starliner. The astronauts will now return on the Crew-9 capsule, tentatively scheduled for March 19th, along with two astronauts from that mission.

Follow along here for all of the updates on the Crew-10 launch, as well as the return flight of Butch Wilmore and Suni Williams.

Continue Reading

Trending