Cryptobriefing
SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SparkKitty is a newly discovered cross-platform malware that targets mobile users, specifically aiming to steal cryptocurrency wallet seed phrases from photos on both iOS and Android devices. It employs advanced optical character recognition (OCR) to scan photo galleries for sensitive information, particularly screenshots of wallet recovery phrases. The malware was first identified by Kaspersky in early 2024 and publicly detailed in June 2025, indicating it has been active for over a year. SparkKitty was distributed through both the Apple App Store and Google Play, embedded in apps like 币coin and SOEX, which masqueraded as legitimate tools. The malicious applications were removed following Kaspersky's disclosure, but the threat remains significant due to the malware's sophisticated evasion techniques. Users in China and Southeast Asia are particularly affected, with the malware leveraging unauthorized distribution channels as well. The crypto market has not shown immediate signs of disruption following the news.
Key Points: • SparkKitty malware uses OCR to steal crypto wallet seed phrases from mobile photo galleries. • It was distributed via legitimate app stores and unauthorized channels, affecting both iOS and Android. • Kaspersky identified the malware in early 2024, with public details released in June 2025.