SparkKitty Malware Scanned Photos for Crypto Wallet Seeds on App Stores

Cybersecurity firm Check Point detailed how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases. First discovered by Kaspersky in June 2025, the malware spread through Apple's App Store, Google Play, and third-party app stores. The campaign succeeded by distributing trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment apps, with one Android variant downloaded more than 10,000 times before removal. The malware exploited a common security vulnerability: users storing wallet seed phrases as screenshots in their photo libraries.

SparkKitty Distributed Through Trojanized Apps on Major Platforms

Check Point wrote that SparkKitty's presence on both the Apple App Store and Google Play gave it a wide attack surface. On iOS, the malware was distributed through a cryptocurrency app called "币coin" that was available on Apple's App Store. The app concealed its malicious code to evade Apple's review process before requesting access to users' photo libraries. On Android, the malware appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before being removed. Other variants were distributed through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs.

Malware Scanned Photo Libraries for Wallet Recovery Phrases

After users granted access to their photo libraries, the malware scanned stored images for wallet recovery phrases and other sensitive information before uploading the data to attacker-controlled servers. Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users' photo libraries directly, making screenshots of wallet recovery phrases a prime target. The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment apps, greatly increasing the likelihood of installation by unsuspecting users.

Researchers Recommend Offline Storage for Wallet Phrases

Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers. Check Point warned that storing wallet recovery phrases as screenshots can expose crypto assets to theft.

Related Malware Campaigns Target Cryptocurrency Users

The report follows a string of malware campaigns targeting cryptocurrency users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet apps while stealing messages, passwords, photos, and other data from vulnerable iPhones. That same month, the FBI launched an investigation after several games distributed through Valve's Steam platform—including "Chemia," "PirateFi," and "Tokenova"—were found to install malware. In May, AI startup Perplexity open-sourced Bumblebee, a security tool designed to detect compromised software packages, browser extensions, and AI connector configurations without executing potentially malicious code following a software supply-chain attack that affected more than 160 developer packages. In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. The campaign deployed Lumma and Vidar infostealers, malware commonly used to steal browser credentials and cryptocurrency wallet data.

FAQ

What is SparkKitty malware and how does it target cryptocurrency users? SparkKitty is malware discovered by Kaspersky in June 2025 that scans users' photo libraries for crypto wallet seed phrases and other sensitive information. It was distributed through trojanized apps on Apple's App Store, Google Play, and third-party app stores, disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment apps.

How many times was the SparkKitty Android app downloaded before removal? The Android variant called SOEX, which appeared as a messaging and cryptocurrency exchange app, was downloaded more than 10,000 times from Google Play before being removed.

What security measures do researchers recommend to protect wallet recovery phrases? Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments