SparkKitty Malware Stole Crypto Recovery Phrases From iPhone and Android Photos

Key Takeaways
  • SparkKitty malware infiltrated Apple's App Store and Google Play, scanning photo libraries for cryptocurrency wallet recovery phrases using optical character recognition.
  • SparkKitty operated inside the iOS app 币coin and Android app SOEX, which surpassed 10,000 downloads on Google Play before removal.
  • Both official-store apps have been removed, and variants spread through third-party stores, sideloaded installers, and modified TikTok clones.

Check Point published an analysis on Sunday of SparkKitty, a cross-platform malware that infiltrated Apple's App Store and Google Play and scanned users' photo libraries for cryptocurrency wallet recovery phrases using optical character recognition. Kaspersky discovered the malware in early 2024 and detailed it publicly in June 2025, identifying it as a direct evolution of the SparkCat stealer. The malware operated inside the iOS app 币coin and the Android app SOEX, which surpassed 10,000 downloads on Google Play before removal, though neither Check Point nor Kaspersky published victim counts or loss figures.

SparkKitty Scanned Photo Libraries Using Optical Character Recognition

On iOS, the payload sat inside a cryptocurrency app called 币coin, published on the App Store, which hid its functionality inside obfuscated frameworks to get past Apple's review. Check Point said it remains unclear whether that developer account was compromised or complicit. The Android version arrived in SOEX, an app presented as a messenger with cryptocurrency exchange features, which passed 10,000 downloads on Google Play before it was pulled.

Once granted gallery access, SparkKitty monitored the image directory and periodically scanned its contents with built-in text-recognition libraries, hunting for readable text in screenshots: recovery phrases, passwords and QR codes. Whatever it found went to a command-and-control server along with device identifiers. Both official-store apps have been removed, and the indicator list Check Point published carries entries dated June 2025 alongside newer ones from April 2026.

Malware Spread Through Official App Stores and Modified Applications

Variants also spread through third-party stores and sideloaded installers, including modified TikTok clones and gambling apps, and used Xposed framework modules to persist on rooted devices. Kaspersky researcher Sergey Puzan said an infected build of TikTok also embedded links to a suspicious store in the victim's profile during sign-in.

Check Point mapped the campaign to techniques including delivering a malicious app through an authorised app store and collecting stored application data. A further SparkCat variant turned up in iOS and Android apps in April 2026, going after the same recovery-phrase images.

Kaspersky and Check Point Researchers Detailed Malware Operation

"The attackers may later try to find various confidential data in the images, for instance, crypto wallet recovery phrases to access the victims' assets," Kaspersky researcher Dmitry Kalinin said when the malware was disclosed. According to Check Point and Kaspersky, SparkKitty is a direct evolution of SparkCat, an earlier information stealer that had been scanning image galleries since at least March 2024.

FAQ

What did SparkKitty malware do on iOS and Android devices?

SparkKitty scanned users' photo libraries using optical character recognition to find cryptocurrency wallet recovery phrases, passwords, and QR codes stored in screenshots, then sent the data to a command-and-control server.

How did SparkKitty reach Apple's App Store and Google Play?

The malware hid inside the iOS app 币coin using obfuscated frameworks to bypass Apple's review, and inside the Android app SOEX, which was presented as a messenger with cryptocurrency exchange features and reached over 10,000 downloads on Google Play before removal.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments