SparkKitty malware found in app stores targets crypto wallet seed phrases
A new malware campaign named SparkKitty is targeting cryptocurrency users by scanning their phone's photo library for wallet seed phrases, according to a report from cybersecurity firm Check Point. The malware was distributed through trojanized apps on both Apple's App Store and Google Play, with one app reaching over 10,000 downloads. This highlights the risk of storing recovery phrases as screenshots and is part of a wider trend of attacks on crypto assets.
SparkKitty malware operation
▪After scanning, the malware uploads the stolen data to servers controlled by the attackers.
▪The SparkKitty campaign was first discovered by the cybersecurity firm Kaspersky in June 2025.
▪A detailed analysis of the SparkKitty campaign was published by the cybersecurity firm Check Point.
▪SparkKitty malware scans users' photo libraries for crypto wallet seed phrases and other sensitive information.
Distribution through app stores
▪On iOS, the malware was hidden in a cryptocurrency app named "币coin" that was available on Apple's App Store.
▪SparkKitty was distributed through malicious apps on Apple's App Store, Google Play, and third-party app stores.
▪On Android, SparkKitty was found in a messaging and crypto exchange app called SOEX, which had over 10,000 downloads from Google Play.
▪The iOS app concealed its malicious code to bypass Apple's review process before requesting photo library access.
Photo library scanning technique
▪SparkKitty's technique of directly searching photo libraries differs from malware that uses clipboard monitoring or keylogging.
▪The malware's photo scanning technique makes screenshots of wallet recovery phrases a prime target for theft.
Security recommendations
▪Users are advised to limit photo library permissions to trusted applications and download software only from reputable developers.
▪Security researchers recommend keeping wallet recovery phrases offline rather than storing them as digital screenshots.
Related cryptocurrency malware campaigns
▪The FBI launched an investigation in March into malware installed via games on Valve's Steam platform, including “Chemia,” “PirateFi,” and “Tokenova”.
▪In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware to steal data from vulnerable iPhones.
▪In June, Kaspersky reported that attackers used Steam Workshop to distribute Lumma and Vidar infostealers disguised as desktop wallpapers.
Story comments
Loading comments…