SparkKitty Malware Targets Crypto Users with Sneaky Photo Library Scans
A new report from cybersecurity firm Check Point has revealed that SparkKitty malware was distributed through malicious apps on Apple's App Store, Google Play, and third-party app stores. This malware campaign targeted cryptocurrency users by scanning their photo libraries for wallet recovery phrases and other sensitive information.
The malware spread across both iOS and Android devices, with the cryptocurrency app '币coin' being a key vector for infection on iOS. On Android, it was distributed through a messaging and cryptocurrency exchange app called SOEX, which was downloaded over 10,000 times from Google Play before being removed.
Unlike other information stealers that rely on clipboard monitoring or keylogging, SparkKitty directly searched users' photo libraries for wallet recovery phrases. Researchers warn that storing these phrases as screenshots can expose crypto assets to theft.