{"id":8336,"date":"2025-02-06T20:20:10","date_gmt":"2025-02-06T20:20:10","guid":{"rendered":"https:\/\/howtogeek.blog\/cs\/?p=8336"},"modified":"2025-02-06T20:20:10","modified_gmt":"2025-02-06T20:20:10","slug":"first-instances-of-malwareinfected-ios-apps-with-screen-reading-capabilities-discovered-in-app-store","status":"publish","type":"post","link":"https:\/\/howtogeek.blog\/cs\/first-instances-of-malwareinfected-ios-apps-with-screen-reading-capabilities-discovered-in-app-store\/","title":{"rendered":"Prvn\u00ed instance aplikac\u00ed pro iOS infikovan\u00fdch malwarem s mo\u017enostmi \u010dten\u00ed obrazovky objeven\u00fdmi v App Store"},"content":{"rendered":"<h2>Vznikaj\u00edc\u00ed hrozba: Malware objeven v aplikac\u00edch pro iOS z Apple App Store a Google Play Store<\/h2>\n<p>V\u011bt\u0161ina u\u017eivatel\u016f iPhon\u016f v\u011b\u0159\u00ed, \u017ee jejich za\u0159\u00edzen\u00ed si p\u0159i stahov\u00e1n\u00ed aplikac\u00ed udr\u017e\u00ed robustn\u00ed \u0161t\u00edt proti malwaru. Historicky to bylo podporov\u00e1no p\u0159\u00edsn\u00fdm procesem prov\u011b\u0159ov\u00e1n\u00ed aplikac\u00ed spole\u010dnosti Apple. Ned\u00e1vn\u00e1 zpr\u00e1va spole\u010dnosti Kaspersky v\u0161ak odhaluje znepokojiv\u00fd pr\u016flom v zabezpe\u010den\u00ed mobiln\u00edch za\u0159\u00edzen\u00ed: v App Store se poprv\u00e9 objevily instance malwaru iOS, kter\u00fd obsahuje technologii OCR zam\u011b\u0159enou na extrahov\u00e1n\u00ed citliv\u00fdch informac\u00ed ze sn\u00edmk\u016f obrazovky u\u017eivatel\u016f.<\/p>\n<h2>Pochopen\u00ed malwaru SparkCat<\/h2>\n<p>Podle zji\u0161t\u011bn\u00ed spole\u010dnosti Kaspersky je tento malware \u2013 p\u0159ezd\u00edvan\u00fd \u201eSparkCat\u201c aktivn\u00ed od b\u0159ezna 2024 a byl identifikov\u00e1n v n\u011bkolika aplikac\u00edch v Apple App Store a Google Play Store. Tento sofistikovan\u00fd malware vyu\u017e\u00edv\u00e1 plugin OCR odvozen\u00fd z knihovny ML Kit spole\u010dnosti Google, kter\u00fd mu umo\u017e\u0148uje skenovat a \u010d\u00edst text extrahovan\u00fd ze sn\u00edmk\u016f obrazovky ulo\u017een\u00fdch ve fotogalerii za\u0159\u00edzen\u00ed.<\/p>\n<h2>Prim\u00e1rn\u00ed hrozba: Zabezpe\u010den\u00ed pen\u011b\u017eenky kryptom\u011bn<\/h2>\n<p>Prim\u00e1rn\u00ed c\u00edl malwaru SparkCat je alarmuj\u00edc\u00ed: vyhled\u00e1v\u00e1 fr\u00e1ze pro obnoven\u00ed pro kryptopen\u011b\u017eenky ulo\u017een\u00e9 jako obr\u00e1zky. Jakmile jsou tyto obnovovac\u00ed fr\u00e1ze identifikov\u00e1ny, mohou b\u00fdt p\u0159ed\u00e1ny \u00fato\u010dn\u00edkovi, kter\u00fd pak m\u016f\u017ee p\u0159evz\u00edt kontrolu nad kryptopen\u011b\u017eenkou, co\u017e vede k potenci\u00e1ln\u00ed kr\u00e1de\u017ei cenn\u00fdch kryptom\u011bn. Pro u\u017eivatele, kte\u0159\u00ed jsou zvykl\u00ed na zabezpe\u010den\u00ed sv\u00fdch pen\u011b\u017eenek, je t\u0159eba poznamenat, \u017ee d\u016fvtipn\u00ed jedinci obvykle vid\u00ed obnovovac\u00ed nebo po\u010d\u00e1te\u010dn\u00ed fr\u00e1zi pouze jednou b\u011bhem vytv\u00e1\u0159en\u00ed pen\u011b\u017eenky a d\u016frazn\u011b se doporu\u010duje uchov\u00e1vat tyto d\u016fle\u017eit\u00e9 informace na bezpe\u010dn\u00e9m offline m\u00edst\u011b, nikoli jako sn\u00edmek obrazovky.<\/p>\n<h3>\u0160ir\u0161\u00ed d\u016fsledky pro bezpe\u010dnost dat<\/h3>\n<p>Zat\u00edmco zac\u00edlen\u00ed na fr\u00e1ze kryptopen\u011b\u017eenky je prim\u00e1rn\u00edm c\u00edlem, kapacita malwaru p\u0159esahuje kryptom\u011bny. Dok\u00e1\u017ee tak\u00e9 vyhled\u00e1vat a zachycovat dal\u0161\u00ed citliv\u00e1 hesla, \u010d\u00edm\u017e vytv\u00e1\u0159\u00ed \u0161ir\u0161\u00ed riziko pro zabezpe\u010den\u00ed u\u017eivatelsk\u00fdch dat nap\u0159\u00ed\u010d r\u016fzn\u00fdmi platformami.<\/p>\n<h2>Dot\u010den\u00e9 aplikace: Na co si d\u00e1t pozor<\/h2>\n<p>Mezi aplikacemi kompromitovan\u00fdmi t\u00edmto malwarem jsou:<\/p>\n<ul>\n<li><strong>WeTink<\/strong> \u2013 Chatovac\u00ed aplikace zalo\u017een\u00e1 na um\u011bl\u00e9 inteligenci<\/li>\n<li><strong>AnyGPT<\/strong> \u2013 Dal\u0161\u00ed chatovac\u00ed slu\u017eba AI<\/li>\n<li><strong>ComeCome<\/strong> \u2013 aplikace pro rozvoz j\u00eddla<\/li>\n<\/ul>\n<p>Navzdory v\u00e1\u017en\u00fdm d\u016fsledk\u016fm jejich bezpe\u010dnostn\u00edch slabin jsou v\u0161echny tyto t\u0159i aplikace st\u00e1le dostupn\u00e9 ke sta\u017een\u00ed v App Store.<\/p>\n<h2>Povaha vkl\u00e1d\u00e1n\u00ed k\u00f3du<\/h2>\n<p>Spole\u010dnost Kaspersky mus\u00ed je\u0161t\u011b ur\u010dit, zda tato integrace k\u00f3du byla z\u00e1m\u011brnou iniciativou v\u00fdvoj\u00e1\u0159\u016f nebo ne\u00famysln\u00fdm d\u016fsledkem \u00fatoku na dodavatelsk\u00fd \u0159et\u011bzec. V ka\u017ed\u00e9m p\u0159\u00edpad\u011b takov\u00e1 nejistota podtrhuje d\u016fle\u017eitost ostra\u017eitosti p\u0159ed malwarov\u00fdmi hrozbami.<\/p>\n<h2>Preventivn\u00ed opat\u0159en\u00ed pro u\u017eivatele<\/h2>\n<p>Pro u\u017eivatele iPhone je z\u00e1sadn\u00ed obranou proti neopr\u00e1vn\u011bn\u00e9mu vyt\u011b\u017eov\u00e1n\u00ed dat omezen\u00ed p\u0159\u00edstupu aplikac\u00ed do va\u0161\u00ed knihovny fotografi\u00ed. Chcete-li zv\u00fd\u0161it zabezpe\u010den\u00ed, postupujte takto:<\/p>\n<ul>\n<li>P\u0159ejd\u011bte na <code>Settings<\/code>.<\/li>\n<li>Vyberte <code>Privacy &amp; Security<\/code>.<\/li>\n<li>Klepnut\u00edm na <code>Photos<\/code>zobraz\u00edte, kter\u00e9 aplikace maj\u00ed p\u0159\u00edstup.<\/li>\n<li>Zkontrolujte a omezte p\u0159\u00edstupov\u00e1 opr\u00e1vn\u011bn\u00ed pro v\u0161echny aplikace, kter\u00e9 nevy\u017eaduj\u00ed \u00fapln\u00fd p\u0159\u00edstup.<\/li>\n<\/ul>\n<p>Tyto mal\u00e9 \u00fapravy mohou v\u00fdrazn\u011b pos\u00edlit va\u0161i obranu proti potenci\u00e1ln\u00edm hrozb\u00e1m.<\/p>\n<h2>Z\u016fsta\u0148te informov\u00e1ni<\/h2>\n<p>Dal\u0161\u00ed technick\u00e9 informace o malwaru a \u00fapln\u00fd seznam dot\u010den\u00fdch r\u00e1mc\u016f iOS naleznete v podrobn\u00e9 <a href=\"https:\/\/securelist.com\/sparkcat-stealer-in-app-store-and-google-play\/115385\/.how\" rel=\"noopener noreferrer nofollow\">zpr\u00e1v\u011b spole\u010dnosti Kaspersky<\/a>.<\/p>\n<p>Chcete-li z\u00edskat pr\u016fb\u011b\u017en\u00e9 aktualizace zabezpe\u010den\u00ed, v\u010detn\u011b odstra\u0148ov\u00e1n\u00ed aplikac\u00ed a pou\u017eiteln\u00fdch pokyn\u016f, dr\u017ete krok se spolehliv\u00fdmi zdroji technick\u00fdch zpr\u00e1v a dodr\u017eujte bezpe\u010dnostn\u00ed doporu\u010den\u00ed.<\/p>\n<h2>\u010casto kladen\u00e9 ot\u00e1zky<\/h2>\n<h3><strong>1. Co m\u00e1m d\u011blat, kdy\u017e si st\u00e1hnu posti\u017eenou aplikaci?<\/strong><\/h3>\n<p>Pokud jste si n\u011bkterou z t\u011bchto aplikac\u00ed st\u00e1hli, je d\u016fle\u017eit\u00e9 ji okam\u017eit\u011b odinstalovat. Zkontrolujte tak\u00e9 svou kryptopen\u011b\u017eenku a zm\u011b\u0148te fr\u00e1zi pro obnoven\u00ed, pokud m\u00e1te podez\u0159en\u00ed, \u017ee va\u0161e informace mohly b\u00fdt kompromitov\u00e1ny.<\/p>\n<h3><strong>2. Jak zjist\u00edm, zda je sta\u017een\u00ed aplikace bezpe\u010dn\u00e9?<\/strong><\/h3>\n<p>P\u0159ed sta\u017een\u00edm jak\u00e9koli aplikace si zkontrolujte u\u017eivatelsk\u00e9 recenze, vyhledejte d\u016fv\u011bryhodn\u00e1 hodnocen\u00ed a ujist\u011bte se, \u017ee poch\u00e1z\u00ed od d\u016fv\u011bryhodn\u00e9ho vydavatele. V\u017edy je vhodn\u00e9 prozkoumat potenci\u00e1ln\u00ed bezpe\u010dnostn\u00ed probl\u00e9my souvisej\u00edc\u00ed s konkr\u00e9tn\u00edmi aplikacemi.<\/p>\n<h3><strong>3. Je iOS proti malwaru bezpe\u010dn\u011bj\u0161\u00ed ne\u017e Android?<\/strong><\/h3>\n<p>Zat\u00edmco iOS je tradi\u010dn\u011b pova\u017eov\u00e1n za bezpe\u010dn\u011bj\u0161\u00ed d\u00edky sv\u00e9mu kontrolovan\u00e9mu prost\u0159ed\u00ed, v\u00fdskyt hrozeb, jako je malware SparkCat, ukazuje, \u017ee \u017e\u00e1dn\u00e1 platforma nen\u00ed imunn\u00ed v\u016f\u010di zranitelnostem. Ostra\u017eitost a proaktivn\u00ed bezpe\u010dnostn\u00ed opat\u0159en\u00ed jsou z\u00e1sadn\u00ed pro v\u0161echny mobiln\u00ed u\u017eivatele.<\/p>\n<p><a class=\"xiaomi\" href=\"https:\/\/allthings.how\/malware-infected-ios-apps-with-screen-reading-found-in-app-store-for-the-first-time\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Zdroj a obr\u00e1zky<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Vznikaj\u00edc\u00ed hrozba: Malware objeven v aplikac\u00edch pro iOS z Apple App Store a Google Play Store V\u011bt\u0161ina u\u017eivatel\u016f iPhon\u016f v\u011b\u0159\u00ed, \u017ee jejich za\u0159\u00edzen\u00ed si p\u0159i stahov\u00e1n\u00ed aplikac\u00ed udr\u017e\u00ed robustn\u00ed \u0161t\u00edt proti malwaru. Historicky to bylo podporov\u00e1no p\u0159\u00edsn\u00fdm procesem prov\u011b\u0159ov\u00e1n\u00ed aplikac\u00ed spole\u010dnosti Apple. Ned\u00e1vn\u00e1 zpr\u00e1va spole\u010dnosti Kaspersky v\u0161ak odhaluje znepokojiv\u00fd pr\u016flom v zabezpe\u010den\u00ed mobiln\u00edch za\u0159\u00edzen\u00ed: v [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[9],"class_list":["post-8336","post","type-post","status-publish","format-standard","hentry","category-how-to","tag-iphone"],"acf":[],"_links":{"self":[{"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/posts\/8336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/comments?post=8336"}],"version-history":[{"count":1,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/posts\/8336\/revisions"}],"predecessor-version":[{"id":8337,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/posts\/8336\/revisions\/8337"}],"wp:attachment":[{"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/media?parent=8336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/categories?post=8336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/howtogeek.blog\/cs\/wp-json\/wp\/v2\/tags?post=8336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}