SparkKitty Malware in App Stores Scans Photos for Crypto Seed Phrases

 

By Muhammad Hassan // July 28, 2026 @ 11:42 AM Make AlphaWire Logo preferred on Google News
SparkKitty Malware in App Stores Scans Photos for Crypto Seed Phrases

Share

Points of Focus

  • SparkKitty malware scanned photos for crypto wallet seed phrases through malicious mobile apps.
  • The malware spread via Apple’s App Store, Google Play, and third-party app stores.
  • Security researchers warn screenshots of recovery phrases can expose crypto wallets to theft.

 

A new report from cybersecurity firm Check Point details how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases and other sensitive data. The malware targeted screenshots already stored in users’ photo libraries instead of relying on typed credentials, giving attackers another route to sensitive wallet credentials.

 

 

SparkKitty scanned photos for wallet recovery phrases

Kaspersky first documented SparkKitty in June 2025 after tracing activity back to at least February 2024. Researchers linked the malware to SparkCat, an earlier campaign that also relied on optical character recognition to identify sensitive text inside images. Check Point’s latest report details how the malware spread across mobile platforms and extracted wallet recovery phrases from users’ photo libraries.

Check Point said the malware spread through trojanized applications disguised as cryptocurrency services, messaging platforms, and entertainment apps. On iOS, researchers found the malicious code inside a crypto-related app called “币coin.” On Android, SparkKitty appeared in the SOEX messaging application with cryptocurrency exchange features, which exceeded 10,000 downloads on Google Play before its removal. Researchers also identified variants distributed through third-party app stores, sideloaded APKs, modified TikTok apps, and gambling software.

 

Photo permissions became the attack path

Once users granted photo library access, SparkKitty scanned stored and newly added images for wallet seed phrases, passwords, and QR codes before sending the extracted information, along with device data, to attacker-controlled servers. The malware targeted sensitive data that users had already saved instead of waiting for them to enter it.

Check Point said users who keep wallet recovery phrases as screenshots face the greatest exposure because anyone with a complete seed phrase can restore a compatible wallet on another device. The company recommends storing recovery phrases offline, limiting photo permissions to trusted applications, and reviewing installed apps regularly.

 

Recent malware trend keeps pressure on crypto users

SparkKitty follows several recent malware campaigns that have targeted cryptocurrency wallet recovery phrases instead of login credentials alone. Recent incidents have included malicious NPM packages designed to capture wallet mnemonics and malware families that combine screenshot theft with clipboard monitoring. At the same time, Check Point didn’t disclose how many wallets were compromised or the value of cryptocurrency stolen through SparkKitty. Both affected applications have since been removed from Apple’s App Store and Google Play.

Share

Default avatar

Muhammad Hassan

Muhammad Hassan is a tech writer with over 11 years of experience in the crypto space. He specializes in crafting data-driven strategic content that helps blockchain and fintech brands grow their organic reach. He has led editorial initiatives for global crypto media outlets, where his strategies and article series have reached millions of readers worldwide.

Table of content

Ad

Related Articles