Malware Targets Cryptocurrency Wallets through Hidden Seed Phrases
Cybersecurity firm Cyberint, part of Check Point, has released a report on the information-stealing malware 'SparkKitty' that targets Android and iOS devices. The report explains how Kaspersky discovered and analyzed SparkKitty.
SparkKitty is an information-stealing malware that sends infected device images to attackers' servers. If the images contain sensitive data such as seed phrases, passwords, or QR codes for cryptocurrency wallets, this information may be leaked.
The report states that if a seed phrase is exposed, it may lead to unauthorized access and transfer of cryptocurrencies from compromised wallets. Check Point warns users who save their seed phrases in image format on their devices are at high risk.
Cyberint discovered SparkKitty was distributed through Apple's App Store and Google Play, as well as third-party app stores and side-loading methods. The report found malicious code embedded in the cryptocurrency-related apps 'Bi Coin' for iOS and 'SOEX' for Android, with over 10,000 downloads before being removed from Google Play.