Malware Campaign Scans Photo Libraries for Crypto Wallet Seed Phrases
Researchers at Check Point have discovered a malware campaign called SparkKitty that targeted cryptocurrency users by scanning their photo libraries for wallet recovery phrases and other sensitive information. The malware was distributed through malicious apps on Apple's App Store, Google Play, and third-party app stores.
The campaign, first discovered by Kaspersky in June 2025, spread through a variety of channels, including the Apple App Store and Google Play. Check Point found that SparkKitty was disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment apps, making it more likely to be installed by unsuspecting users.
Once installed, SparkKitty granted access to the user's photo library and searched for wallet recovery phrases and other sensitive information before uploading the data to attacker-controlled servers. Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty directly scanned users' photo libraries, making screenshots of wallet recovery phrases a prime target.
Check Point recommends keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers. This is the latest in a string of malware campaigns targeting cryptocurrency users, with several recent incidents involving DarkSword, Ghostblade, Lumma, and Vidar infostealers.