Hackers are targeting apps on the App Store and Google Play Store with malware that steals information from screenshots saved on a device, according to Kaspersky researchers. The malware scans screenshots, extracts text, and sends the information to remote servers, potentially accessing contents including crypto wallet recovery phrases, login credentials, and payment details. The malware has infected apps including ComeCome, ChatAi, WeTink, AnyGPT. Apple and Google have removed the infected apps and are reviewing their security procedures to avoid similar incidents in the future.
![](https://healsecurity.com/wp-content/uploads/2025/02/winnti20hackers20attacking20japanese20organizations20with20new20malware.webp.jpeg)
Winnti Hackers Attacking Japanese Organizations With New Malware
The China-based Winnti Group has targeted Japanese firms in key sectors such as manufacturing, materials, and energy, using a cyberattack campaign known as “RevivalStone.” Employing