Cryptobriefing SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries
Article Content
- •SparkKitty malware targets cryptocurrency users by scanning photos for sensitive data.
- •It spreads through legitimate-looking apps on both the Apple App Store and Google Play.
- •Users are advised to avoid storing wallet recovery phrases in screenshots and limit app permissions.
SparkKitty is a newly identified cross-platform malware that targets cryptocurrency users by scanning photos on both iOS and Android devices for wallet recovery phrases. It spreads through trojanized applications disguised as legitimate tools, such as a cryptocurrency tracking app called 币coin on the App Store and a messaging app named SOEX on Google Play, which had over 10,000 downloads before removal. The malware employs optical character recognition (OCR) to extract sensitive information from images, including screenshots of wallet seed phrases. This threat is notable for its ability to bypass security measures in both app stores, raising concerns about the effectiveness of current vetting processes. Kaspersky first reported SparkKitty in June 2025, and it appears to be an evolution of a previous malware known as SparkCat. Users are advised to limit photo library permissions and avoid storing sensitive information in screenshots. Both Apple and Google have removed the infected applications following disclosures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Ghostblade in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Soon After Patch Release On September 10, 2026, GitLab released versions 19.3.2, 19.2.6, and 19.1.8 to address critical vulnerabilities, including CVE-2026-85706, a path traversal flaw with a CVSS score of 10.0, allowing unauthenticated users to read arbitrary files from the server. Within hours of the patch, active exploitation attempts were…