SparkKitty Mobile Spyware Campaign Targets Android and iOS Users
Kaspersky researchers have discovered a cross-platform mobile spyware campaign called SparkKitty that targets both Android and iOS users through trojanized cryptocurrency, gambling, and TikTok-themed applications. The malware steals photos and device information, with attackers believed to be searching for cryptocurrency wallet recovery phrases, passwords, and other sensitive content stored in image galleries.
SparkKitty has been active since at least February 2024 and is linked to the earlier SparkCat campaign. Both threats use malicious components hidden inside otherwise functional applications, demonstrating how threat actors can abuse trusted distribution channels as well as unofficial download sites.
On iOS, Kaspersky identified SparkKitty in a cryptocurrency-related application named 币coin, which was available through Apple’s App Store before being removed. Researchers also found malicious TikTok and gambling app variants distributed through phishing pages that impersonated the App Store.