Cryptobriefing
SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SparkKitty is a newly identified cross-platform malware that targets cryptocurrency users by scanning photos on both iOS and Android devices for wallet recovery phrases. It spreads through trojanized applications disguised as legitimate tools, such as a cryptocurrency tracking app called 币coin on the App Store and a messaging app named SOEX on Google Play, which had over 10,000 downloads before removal. The malware employs optical character recognition (OCR) to extract sensitive information from images, including screenshots of wallet seed phrases. This threat is notable for its ability to bypass security measures in both app stores, raising concerns about the effectiveness of current vetting processes. Kaspersky first reported SparkKitty in June 2025, and it appears to be an evolution of a previous malware known as SparkCat. Users are advised to limit photo library permissions and avoid storing sensitive information in screenshots. Both Apple and Google have removed the infected applications following disclosures.
Key Points: • SparkKitty malware targets cryptocurrency users by scanning photos for sensitive data. • It spreads through legitimate-looking apps on both the Apple App Store and Google Play. • Users are advised to avoid storing wallet recovery phrases in screenshots and limit app permissions.