SparkKitty Malware Scans Mobile Photos for Crypto Wallet Seed Phrases

Key Takeaways
  • SparkKitty malware distributed through Apple App Store and Google Play targets cryptocurrency users by scanning photos for wallet seed phrases.
  • SOEX Android application containing SparkKitty accumulated over 10,000 downloads before removal from Google Play.
  • Check Point recommends storing cryptocurrency wallet recovery phrases offline rather than as device screenshots or photos.

SparkKitty malware has been distributed through Apple's App Store, Google Play, and third-party Android app stores, targeting cryptocurrency users by scanning photos for wallet recovery phrases, according to a Check Point report published Sunday. The malware uses optical character recognition (OCR) to search images stored on infected devices for cryptocurrency wallet seed phrases, allowing attackers to extract sensitive credentials without keystroke logging or clipboard monitoring. Check Point identified SparkKitty as an evolution of SparkCat, an OCR-based stealer documented by Kaspersky, noting the malware spreads through trojanized applications masquerading as cryptocurrency services, messaging platforms, and entertainment apps.

SparkKitty Uses OCR to Extract Wallet Credentials from Photos

Once installed, the applications request permission to access a user's photo library before continuously scanning existing and newly added images. Text extracted from images, including wallet seed phrases, passwords, and QR code data, is transmitted to attacker-controlled command-and-control infrastructure together with basic device information, according to the report. Check Point stated that users who store wallet recovery phrases as screenshots or photographs face the greatest exposure, because possession of a seed phrase enables complete access to a compatible cryptocurrency wallet.

iOS App 币coin Distributed Malware Through Apple App Store

On iOS, Check Point said the malware was embedded in a cryptocurrency-related application called "币coin" that was available through the App Store. The malicious functionality was concealed within obfuscated frameworks, including AFNetworking and libswiftDarwin.dylib, enabling the application to pass Apple's review process, according to the report. It remains unclear whether the developer account behind the application was compromised or knowingly involved.

Android App SOEX Accumulated 10,000+ Downloads Before Removal

On Android, researchers identified SparkKitty inside an application called "SOEX," which presented itself as a messaging and cryptocurrency exchange platform. The application accumulated more than 10,000 downloads on Google Play before being removed, according to Check Point. The report stated additional Android variants were distributed through third-party app stores, sideloaded APKs, modified TikTok applications, and gambling apps. On rooted devices, some samples used Xposed framework modules to maintain persistence.

Check Point Recommends Offline Storage for Wallet Recovery Phrases

The report recommends avoiding screenshots of wallet recovery phrases, restricting photo library permissions to applications that require them, downloading software only from trusted sources, and reviewing application permissions regularly. Check Point also advises storing recovery phrases offline, such as on paper or in hardware wallet backup solutions, rather than in a device's photo gallery.

FAQ

What does SparkKitty malware do on infected mobile devices? SparkKitty uses optical character recognition (OCR) to scan images stored on infected devices for cryptocurrency wallet seed phrases, passwords, and QR code data. The malware requests permission to access a user's photo library and continuously scans existing and newly added images, transmitting extracted text to attacker-controlled infrastructure.

How many downloads did the SOEX Android app accumulate before removal? The SOEX Android application, which contained SparkKitty malware and presented itself as a messaging and cryptocurrency exchange platform, accumulated more than 10,000 downloads on Google Play before being removed, according to Check Point's report published Sunday.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments