A mobile malware campaign spread through the Apple App Store and Google Play Store hacked into users 'photo libraries to search for cryptocurrency wallet recovery phrases and other sensitive data.
Malware masquerades as cryptocurrency, communications and entertainment applications
Recent analysis by Check Point's external risk management team details how SparkKitty spreads-it spreads through applications masquerades as cryptocurrency services, communications platforms and entertainment products. The malware targets both Android and iOS devices through official app stores, third-party marketplaces, and side-loaded app packages.
Kaspersky first recorded SparkKitty in June 2025 and traced the activity to at least February 2024. The latest report once again focuses on the malware's ability to recognize wallet credentials stored in screenshots and photos, rather than waiting for users to enter credentials into phishing pages. On the iOS platform, malicious code appears in a cryptocurrency-related application called "coin". Android users encountered SparkKitty through a messaging app called SOEX, which also promoted cryptocurrency trading capabilities. SOEX passed Google Play's review process and accumulated more than 10,000 downloads until Google removed it after receiving a security notice. Apple also removed affected iOS apps.
Photo permissions cause wallet backup to be leaked
Infected apps request access to the device's photo gallery while still providing the features shown in their store list. Once granted permission, SparkKitty collects existing images and monitors newly added files. Some versions upload gallery content directly, while relevant samples use optical character recognition technology to filter out images containing recovered phrases, passwords, QR codes and other text. The stolen files are sent along with device information to a command and control server controlled by the attacker.
The complete seed phrase allows an attacker to recover a compatible wallet on another device and transfer assets without having to access the original phone or wallet password. If the user installs the affected app and stores the recovery phrase in the photo gallery, the wallet should be considered compromised. Once the phrase is copied, deleting the photo or uninstalling the app cannot revoke the attacker's access. The remaining assets need to be transferred to a new wallet, which needs to be generated on clean devices using a brand new seed phrase.
Malware activity turns to steal wallet keys
SparkKitty is one of a series of attacks centered on collecting recovery materials that control cryptocurrency wallets. Previously, a tampered Impressive npm package intercepted mnemonic words and private keys when developers created or loaded wallets through a contaminated software development kit. The malicious version spread to 18 packages before being removed and replaced. Microsoft has also traced CryptoBandits malware spread through infected USB drives, which combines seed phrase collection, screenshot theft, clipboard monitoring, and cryptocurrency address replacement capabilities.
Check Point did not disclose the exact number of infected wallets or the value of the cryptocurrency stolen through SparkKitty. Currently, the identified apps are no longer available through the Apple App Store or Google Play Store.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following