Check Point published an analysis on Sunday of SparkKitty, a cross-platform malware that infiltrated Apple's App Store and Google Play and scanned users' photo libraries for cryptocurrency wallet recovery phrases using optical character recognition. Kaspersky discovered the malware in early 2024 and detailed it publicly in June 2025, identifying it as a direct evolution of the SparkCat stealer. The malware operated inside the iOS app 币coin and the Android app SOEX, which surpassed 10,000 downloads on Google Play before removal, though neither Check Point nor Kaspersky published victim counts or loss figures.
SparkKitty Scanned Photo Libraries Using Optical Character Recognition
On iOS, the payload sat inside a cryptocurrency app called 币coin, published on the App Store, which hid its functionality inside obfuscated frameworks to get past Apple's review. Check Point said it remains unclear whether that developer account was compromised or complicit. The Android version arrived in SOEX, an app presented as a messenger with cryptocurrency exchange features, which passed 10,000 downloads on Google Play before it was pulled.
Once granted gallery access, SparkKitty monitored the image directory and periodically scanned its contents with built-in text-recognition libraries, hunting for readable text in screenshots: recovery phrases, passwords and QR codes. Whatever it found went to a command-and-control server along with device identifiers. Both official-store apps have been removed, and the indicator list Check Point published carries entries dated June 2025 alongside newer ones from April 2026.
Malware Spread Through Official App Stores and Modified Applications
Variants also spread through third-party stores and sideloaded installers, including modified TikTok clones and gambling apps, and used Xposed framework modules to persist on rooted devices. Kaspersky researcher Sergey Puzan said an infected build of TikTok also embedded links to a suspicious store in the victim's profile during sign-in.
Check Point mapped the campaign to techniques including delivering a malicious app through an authorised app store and collecting stored application data. A further SparkCat variant turned up in iOS and Android apps in April 2026, going after the same recovery-phrase images.
Kaspersky and Check Point Researchers Detailed Malware Operation
"The attackers may later try to find various confidential data in the images, for instance, crypto wallet recovery phrases to access the victims' assets," Kaspersky researcher Dmitry Kalinin said when the malware was disclosed. According to Check Point and Kaspersky, SparkKitty is a direct evolution of SparkCat, an earlier information stealer that had been scanning image galleries since at least March 2024.
FAQ
What did SparkKitty malware do on iOS and Android devices?
SparkKitty scanned users' photo libraries using optical character recognition to find cryptocurrency wallet recovery phrases, passwords, and QR codes stored in screenshots, then sent the data to a command-and-control server.
How did SparkKitty reach Apple's App Store and Google Play?
The malware hid inside the iOS app 币coin using obfuscated frameworks to bypass Apple's review, and inside the Android app SOEX, which was presented as a messenger with cryptocurrency exchange features and reached over 10,000 downloads on Google Play before removal.