SparkKitty Malware Targets Crypto Seed Phrases in App Store and Google Play
A new strain of malware called SparkKitty has been discovered embedded in apps distributed through both the Apple App Store and Google Play. The malicious software, identified by Kaspersky researchers, uses optical character recognition technology to scan users' photo galleries for screenshots containing crypto wallet seed phrases.
Once it finds a match, the image is exfiltrated to servers controlled by the attackers, who can then reconstruct the wallet and drain its contents. This is particularly concerning because a seed phrase is the master key to a crypto wallet, and there's no 'reset' option once someone has access to it.
The malware has been active since at least February 2024, and has been linked to the SparkCat operation that Kaspersky first reported in January 2025. It was embedded in an app called 币coin on the Apple App Store and SOEX on Google Play, among other apps. Both Apple and Google have removed the infected applications following Kaspersky's disclosure.
The discovery highlights the importance of operational security hygiene for investors, including deleting any screenshots of seed phrases immediately and using a hardware wallet for significant holdings. Users should also be skeptical of app permissions, particularly requests for photo gallery access from apps that have no business viewing their photos.