Scworld SparkCat Malware Targets Crypto Users via App Stores
Article Content
- •SparkCat malware targets cryptocurrency wallet recovery phrases from photo galleries.
- •The malware is found in benign apps on both iOS and Android platforms.
- •Users in Asia are primarily affected, with advanced obfuscation techniques employed.
The SparkCat malware has resurfaced on the Apple App Store and Google Play Store, targeting cryptocurrency users. This Trojan malware, first identified in February 2025, conceals itself within benign applications, including enterprise messengers and food delivery services. It employs optical character recognition (OCR) to scan photo galleries for cryptocurrency wallet recovery phrases. The malware's iOS variant targets English phrases, while the Android version scans for keywords in Japanese, Korean, and Chinese. Cybersecurity firm Kaspersky has reported its ongoing presence, indicating that the same developers are likely behind the new variant. Users in Asia are particularly affected by this evolving threat. Researchers recommend avoiding storing sensitive information in photo galleries and exercising caution with app permissions. The malware's ability to bypass security reviews poses a significant risk to users' cryptocurrency assets.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track SparkCat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…