SparkKitty Malware Exposes Crypto Wallet Recovery Phrases Through Mobile Gallery Images
A mobile spyware campaign known as SparkKitty has been targeting iOS and Android users by stealing gallery images, including cryptocurrency wallet recovery phrases. The malware gains photo access, collects images, and sends them to attacker-controlled servers.
According to researchers, the campaign had operated since at least February 2024 and mainly targeted Southeast Asia and China. SparkKitty was found in fake crypto tools, modified social apps, gambling products, and other applications on unofficial stores and even some official app stores like Apple's App Store and Google Play.
Kaspersky reported a new SparkCat variant in April 2026, showing continued use of OCR-based gallery theft. The researchers advise users to store wallet recovery phrases offline securely, review photo permissions, and remove access from apps that do not need it.