SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a stealer known as SparkCat. Unlike traditional malware focused on keylogging or clipboard hijacking, SparkKitty specializes in analyzing images stored on the infected device, extracting textual information from screenshots, and uploading it to a remote command-and-control (C2) server.
What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface. The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.
SparkKitty was primarily distributed via two methods: official app store uploads and sideloaded applications.
On iOS, the malicious payload was embedded inside a cryptocurrency-related app titled “币coin” that was published through the App Store. While it is still unclear whether the developer account was compromised or complicit, the app managed to bypass Apple’s security vetting process by hiding malicious functionality within obfuscated frameworks such as AFNetworking and libswiftDarwin.dylib. These modules were crafted to appear legitimate, enabling SparkKitty to avoid detection.
The Android version was delivered through a widely distributed app named “SOEX,” which was available on Google Play and had amassed more than 10,000 downloads before its removal. This application posed as a messaging and cryptocurrency exchange platform but secretly included functionality to access the device’s media storage, monitor file changes, and exfiltrate data. In addition to Google Play, SparkKitty variants were also found distributed through third-party stores and sideloaded APKs, including modded TikTok clones and gambling apps. On some rooted Android devices, it used advanced persistence techniques through Xposed framework modules.
Once installed, SparkKitty would request access to the photo gallery. Upon receiving permission, it actively monitored the image directory and periodically scanned the contents using built-in OCR libraries. The goal was to locate and extract readable text from screenshots, especially those likely to contain sensitive financial data such as seed phrases, passwords, or QR codes. The extracted data, along with device metadata, would then be uploaded silently to the threat actor’s infrastructure.
SparkKitty was primarily distributed via two methods: official app store uploads and sideloaded applications.
On iOS, the malicious payload was embedded inside a cryptocurrency-related app titled “币coin” that was published through the App Store. While it is still unclear whether the developer account was compromised or complicit, the app managed to bypass Apple’s security vetting process by hiding malicious functionality within obfuscated frameworks such as AFNetworking and libswiftDarwin.dylib. These modules were crafted to appear legitimate, enabling SparkKitty to avoid detection.
The Android version was delivered through a widely distributed app named “SOEX,” which was available on Google Play and had amassed more than 10,000 downloads before its removal. This application posed as a messaging and cryptocurrency exchange platform but secretly included functionality to access the device’s media storage, monitor file changes, and exfiltrate data. In addition to Google Play, SparkKitty variants were also found distributed through third-party stores and sideloaded APKs, including modded TikTok clones and gambling apps. On some rooted Android devices, it used advanced persistence techniques through Xposed framework modules.
Once installed, SparkKitty would request access to the photo gallery. Upon receiving permission, it actively monitored the image directory and periodically scanned the contents using built-in OCR libraries. The goal was to locate and extract readable text from screenshots, especially those likely to contain sensitive financial data such as seed phrases, passwords, or QR codes. The extracted data, along with device metadata, would then be uploaded silently to the threat actor’s infrastructure.
Check Point Exposure Management is an intelligence-led, validation-driven, remediation-first unified platform that helps security teams move quickly and safely from exposure visibility to exposure reduction. Delivered through a single UI, it brings together threat intelligence, exposure prioritization, Agentic Exposure Validation, and safe remediation so teams can understand risk, prove exploitability, and act from one place.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
