EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SparkKitty malware in the app store scans photos and steals cryptocurrency seed phrases

2026-07-28 12:56:10
Bookmark

A mobile malware campaign spread through the Apple App Store and Google Play Store hacked into users 'photo libraries to search for cryptocurrency wallet recovery phrases and other sensitive data.

Malware masquerades as cryptocurrency, communications and entertainment applications

Recent analysis by Check Point's external risk management team details how SparkKitty spreads-it spreads through applications masquerades as cryptocurrency services, communications platforms and entertainment products. The malware targets both Android and iOS devices through official app stores, third-party marketplaces, and side-loaded app packages.

Kaspersky first recorded SparkKitty in June 2025 and traced the activity to at least February 2024. The latest report once again focuses on the malware's ability to recognize wallet credentials stored in screenshots and photos, rather than waiting for users to enter credentials into phishing pages. On the iOS platform, malicious code appears in a cryptocurrency-related application called "coin". Android users encountered SparkKitty through a messaging app called SOEX, which also promoted cryptocurrency trading capabilities. SOEX passed Google Play's review process and accumulated more than 10,000 downloads until Google removed it after receiving a security notice. Apple also removed affected iOS apps.

Photo permissions cause wallet backup to be leaked

Infected apps request access to the device's photo gallery while still providing the features shown in their store list. Once granted permission, SparkKitty collects existing images and monitors newly added files. Some versions upload gallery content directly, while relevant samples use optical character recognition technology to filter out images containing recovered phrases, passwords, QR codes and other text. The stolen files are sent along with device information to a command and control server controlled by the attacker.

The complete seed phrase allows an attacker to recover a compatible wallet on another device and transfer assets without having to access the original phone or wallet password. If the user installs the affected app and stores the recovery phrase in the photo gallery, the wallet should be considered compromised. Once the phrase is copied, deleting the photo or uninstalling the app cannot revoke the attacker's access. The remaining assets need to be transferred to a new wallet, which needs to be generated on clean devices using a brand new seed phrase.

Malware activity turns to steal wallet keys

SparkKitty is one of a series of attacks centered on collecting recovery materials that control cryptocurrency wallets. Previously, a tampered Impressive npm package intercepted mnemonic words and private keys when developers created or loaded wallets through a contaminated software development kit. The malicious version spread to 18 packages before being removed and replaced. Microsoft has also traced CryptoBandits malware spread through infected USB drives, which combines seed phrase collection, screenshot theft, clipboard monitoring, and cryptocurrency address replacement capabilities.

Check Point did not disclose the exact number of infected wallets or the value of the cryptocurrency stolen through SparkKitty. Currently, the identified apps are no longer available through the Apple App Store or Google Play Store.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP