SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries

SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries

First seen 27 Jul 2026, 14:34 UTC CybersecuritynewsCryptobriefingCyberint 85% similarity 69.5

Article Content

Browse articles
ThreatCluster

SparkKitty is a newly discovered cross-platform malware that targets mobile users, specifically aiming to steal cryptocurrency wallet seed phrases from photos on both iOS and Android devices. It employs advanced optical character recognition (OCR) to scan photo galleries for sensitive information, particularly screenshots of wallet recovery phrases. The malware was first identified by Kaspersky in early 2024 and publicly detailed in June 2025, indicating it has been active for over a year. SparkKitty was distributed through both the Apple App Store and Google Play, embedded in apps like 币coin and SOEX, which masqueraded as legitimate tools. The malicious applications were removed following Kaspersky's disclosure, but the threat remains significant due to the malware's sophisticated evasion techniques. Users in China and Southeast Asia are particularly affected, with the malware leveraging unauthorized distribution channels as well. The crypto market has not shown immediate signs of disruption following the news.

Key Points: • SparkKitty malware uses OCR to steal crypto wallet seed phrases from mobile photo galleries. • It was distributed via legitimate app stores and unauthorized channels, affecting both iOS and Android. • Kaspersky identified the malware in early 2024, with public details released in June 2025.

ThreatCluster AI How this analysis works

Timeline

2024-02-01
SparkKitty malware first active
Kaspersky researchers linked the malware to ongoing campaigns targeting crypto users.
Cyberint
2025-01-05
SparkCat operation reported
Kaspersky disclosed the SparkCat operation, indicating a connection to SparkKitty.
Cryptobriefing
2025-06-23
SparkKitty publicly detailed
Kaspersky published comprehensive findings on SparkKitty, revealing its methods and targets.
Cryptobriefing
2026-07-27
Malware removed from app stores
Apple and Google removed infected applications following Kaspersky's disclosure of SparkKitty.
Cyberint

Community

Browse all →