Skip to content
SparkCat Malware Targets Crypto Users via App Stores

SparkCat Malware Targets Crypto Users via App Stores

First seen 6 Apr 2026, 15:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 7, 2026 at 15:47 UTC
  • •SparkCat malware targets cryptocurrency wallet recovery phrases from photo galleries.
  • •The malware is found in benign apps on both iOS and Android platforms.
  • •Users in Asia are primarily affected, with advanced obfuscation techniques employed.

The SparkCat malware has resurfaced on the Apple App Store and Google Play Store, targeting cryptocurrency users. This Trojan malware, first identified in February 2025, conceals itself within benign applications, including enterprise messengers and food delivery services. It employs optical character recognition (OCR) to scan photo galleries for cryptocurrency wallet recovery phrases. The malware's iOS variant targets English phrases, while the Android version scans for keywords in Japanese, Korean, and Chinese. Cybersecurity firm Kaspersky has reported its ongoing presence, indicating that the same developers are likely behind the new variant. Users in Asia are particularly affected by this evolving threat. Researchers recommend avoiding storing sensitive information in photo galleries and exercising caution with app permissions. The malware's ability to bypass security reviews poses a significant risk to users' cryptocurrency assets.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 181d ago How this analysis works

Timeline

2025-02-01
SparkCat malware first identified.
2026-04-05
New version of SparkCat discovered on app stores.
2026-04-06
Kaspersky reports ongoing presence of SparkCat.

More articles in this cluster (5)

Following this threat?

Track SparkCat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed