FBI Warns of North Korean Hackers Using Android Malware to Steal Crypto Keys

FBI Hack Scam
SpyAgent targets private keys by leveraging OCR technology to scan and extract text from screenshots.
Author
Author
Ruholamin HaqshanasVerified
Part of the Team Since
Oct 2021
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated: 

The FBI has issued a warning about a sophisticated new Android malware called SpyAgent, discovered by McAfee, which is designed to steal cryptocurrency private keys from users’ smartphones.

SpyAgent targets private keys by leveraging optical character recognition (OCR) technology to scan and extract text from screenshots and images stored on the device.

McAfee’s analysis reveals that SpyAgent is distributed through malicious links sent via text messages.

Malware Masquerades as Various Programs

When users click on these links, they are redirected to seemingly legitimate websites that prompt them to download an app disguised as a trustworthy program.

In reality, this app is the SpyAgent malware, which compromises the phone’s security once installed.

The malware masquerades as various types of applications, including banking apps, government services, and streaming platforms.

Upon installation, it requests permissions to access contacts, messages, and local storage, facilitating its extraction of sensitive data.

McAfee reports that SpyAgent has been detected in over 280 fraudulent apps and is primarily targeting South Korean users.

The alert comes on the heels of another malware threat identified in August.

The “Cthulhu Stealer,” which affects MacOS systems, similarly disguises itself as legitimate software and targets personal information, including MetaMask passwords, IP addresses, and cold wallet private keys.

The same month saw Microsoft uncover a vulnerability in Google Chrome, which North Korean hacker group Citrine Sleet exploited to create fake cryptocurrency exchanges and fraudulent job applications.

These activities led to the installation of remote-controlled malware that also stole private keys.

The vulnerability in Chrome has since been patched, but the rise in these types of cyberattacks has prompted the FBI to issue a formal warning about North Korean hacking activities.

Users are advised to remain vigilant and avoid downloading apps or clicking on links from unknown sources to protect their digital assets from such sophisticated threats.

Crypto Projects Lost $310M to Scams in August

As reported, August saw a surge in crypto-related scams, with a staggering $310 million lost to various exploits, making it the second-highest monthly total this year.

However, $10.3 million of the stolen assets were eventually recovered or returned, leaving the net loss at $300.6 million.

Phishing incidents emerged as the most damaging, accounting for approximately $293 million of the total losses.

Two particularly large-scale phishing attacks resulted in the theft of $238 million in Bitcoin and $55 million in DAI stablecoin.

Aside from phishing, other notable losses in August included attacks on several crypto projects.

For instance, the Ronin Network, an Ethereum Virtual Machine (EVM)-based sidechain, was exploited by a white hat hacker on August 6, resulting in the theft of 4,000 ETH, valued at $9.85 million at the time.

Additionally, flash loan attacks, though still concerning, resulted in relatively lower losses of $1.2 million in August compared to previous months.

In contrast to the rise in phishing and other forms of exploitation, exit scams saw a significant decline, with losses dropping to $800,000 in August, down from around $3 million in July.

In the Article
Bitcoin
BTC
$88,336
0.96 %
Ethereum
ETH
$2,975
1.58 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,118,706,171,698
0.85
Trending Crypto

More Articles

Altcoin News
XRP ETPs Absorb $70M as Institutions Rotate Out of Bitcoin
David Pokima
David Pokima
2025-12-30 17:58:02
News
ElizaOS Price Prediction: ELIZAOS Price Skyrockets 170% in 48 Hours – What Is Going On?
Harvey Hunter
Harvey Hunter
2025-12-30 17:24:27
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors