SparkKitty Malware Steals Crypto Recovery Data Through App Stores
Cyberint has discovered a cross-platform information stealer called SparkKitty that targets iOS and Android users through malicious applications distributed via Apple's App Store, Google Play, and unofficial channels.
The malware seeks access to photo libraries, turning ordinary gallery permissions into a route for harvesting crypto recovery data. This is particularly concerning for users who store wallet seed phrases, private information, or account credentials in screenshots.
Once installed, SparkKitty can exfiltrate images and device data to attacker-controlled infrastructure. This means that a single exposed recovery phrase could give criminals control of an entire wallet, even if the wallet application itself is not compromised.