SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries

SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries

First seen 27 Jul 2026, 14:34 UTC CybersecuritynewsCryptobriefingCyberintTheblock.CoDecrypt.Co+10 87% similarity 71.8

Article Content

Browse articles
ThreatCluster

SparkKitty is a newly identified cross-platform malware that targets cryptocurrency users by scanning photos on both iOS and Android devices for wallet recovery phrases. It spreads through trojanized applications disguised as legitimate tools, such as a cryptocurrency tracking app called 币coin on the App Store and a messaging app named SOEX on Google Play, which had over 10,000 downloads before removal. The malware employs optical character recognition (OCR) to extract sensitive information from images, including screenshots of wallet seed phrases. This threat is notable for its ability to bypass security measures in both app stores, raising concerns about the effectiveness of current vetting processes. Kaspersky first reported SparkKitty in June 2025, and it appears to be an evolution of a previous malware known as SparkCat. Users are advised to limit photo library permissions and avoid storing sensitive information in screenshots. Both Apple and Google have removed the infected applications following disclosures.

Key Points: • SparkKitty malware targets cryptocurrency users by scanning photos for sensitive data. • It spreads through legitimate-looking apps on both the Apple App Store and Google Play. • Users are advised to avoid storing wallet recovery phrases in screenshots and limit app permissions.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
SparkKitty linked to SparkCat malware
SparkKitty is reported as an evolution of the previously identified SparkCat malware.
Cyberint
2025-06-23
Kaspersky publishes findings on SparkKitty
Kaspersky identifies SparkKitty as a cross-platform malware targeting crypto users through photo scanning.
Kaspersky
2026-07-27
SparkKitty discovered in App Store and Google Play
Check Point reports SparkKitty's distribution through trojanized apps on major app stores.
Theblock.Co
2026-07-27
Malicious apps removed from app stores
Apple and Google remove infected applications following Kaspersky's disclosure of SparkKitty.
Cryptobriefing
2026-07-27
Security recommendations issued
Experts recommend avoiding screenshots of wallet recovery phrases and limiting app permissions.
Decrypt.Co

Community

Browse all →