SparkKitty Malware Scans Photo Libraries for Crypto Seed Phrases
A malicious mobile malware campaign called SparkKitty has been discovered on Apple's App Store and Google Play, targeting users' cryptocurrency wallet recovery phrases and other sensitive data.
The analysis from Check Point External Risk Management revealed that SparkKitty spread through applications posing as crypto services, messaging platforms, and entertainment products. The malware accessed Android and iOS devices through official stores, third-party marketplaces, and sideloaded application packages.
SparkKitty identified wallet credentials stored inside screenshots and photographs rather than waiting for users to type them into a phishing page. On iOS, the malicious code appeared in a crypto-related application called 币coin, while Android users encountered SparkKitty through SOEX, a messaging application that also advertised cryptocurrency exchange features.
The infected applications requested access to the device's photo library and once permission was granted, SparkKitty collected existing images and monitored newly added files. Some versions uploaded gallery content directly, while related samples used optical character recognition to select images containing recovery phrases, passwords, QR codes, and other text.