Share
Subscribe to the AlphaWire Newsletter
A new report from cybersecurity firm Check Point details how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases and other sensitive data. The malware targeted screenshots already stored in users’ photo libraries instead of relying on typed credentials, giving attackers another route to sensitive wallet credentials.
🚨WARNING
Apple and Google both approved apps carrying malware that empties crypto wallets.
It's called SparkKitty. Hides inside crypto apps, fake TikTok mods, and one "messaging app" that got 10,000+ downloads on the Play Store.
The trick is stupidly simple. You give it photo… pic.twitter.com/13uTj0eBkc
— Evan Luthra (@EvanLuthra) July 28, 2026
Kaspersky first documented SparkKitty in June 2025 after tracing activity back to at least February 2024. Researchers linked the malware to SparkCat, an earlier campaign that also relied on optical character recognition to identify sensitive text inside images. Check Point’s latest report details how the malware spread across mobile platforms and extracted wallet recovery phrases from users’ photo libraries.
Check Point said the malware spread through trojanized applications disguised as cryptocurrency services, messaging platforms, and entertainment apps. On iOS, researchers found the malicious code inside a crypto-related app called “币coin.” On Android, SparkKitty appeared in the SOEX messaging application with cryptocurrency exchange features, which exceeded 10,000 downloads on Google Play before its removal. Researchers also identified variants distributed through third-party app stores, sideloaded APKs, modified TikTok apps, and gambling software.
Once users granted photo library access, SparkKitty scanned stored and newly added images for wallet seed phrases, passwords, and QR codes before sending the extracted information, along with device data, to attacker-controlled servers. The malware targeted sensitive data that users had already saved instead of waiting for them to enter it.
Check Point said users who keep wallet recovery phrases as screenshots face the greatest exposure because anyone with a complete seed phrase can restore a compatible wallet on another device. The company recommends storing recovery phrases offline, limiting photo permissions to trusted applications, and reviewing installed apps regularly.
SparkKitty follows several recent malware campaigns that have targeted cryptocurrency wallet recovery phrases instead of login credentials alone. Recent incidents have included malicious NPM packages designed to capture wallet mnemonics and malware families that combine screenshot theft with clipboard monitoring. At the same time, Check Point didn’t disclose how many wallets were compromised or the value of cryptocurrency stolen through SparkKitty. Both affected applications have since been removed from Apple’s App Store and Google Play.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share