Overview
- SparkKitty scans users' photo libraries for sensitive information such as crypto wallet seed phrases.
- The malware was found in malicious applications across Apple's App Store, Google Play, and various third-party app stores.
- Experts caution that saving wallet recovery phrases as screenshots increases the risk of theft.
A recent report from cybersecurity firm Check Point outlines the SparkKitty malware campaign, which specifically targets cryptocurrency users by scanning the photo libraries of infected Android and iPhone devices for wallet recovery phrases and other sensitive data.
Initially identified by Kaspersky in June 2025, Check Point's findings reveal how the malware spread through platforms like Apple's App Store, Google Play, and third-party app stores.
Check Point noted, “What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface. The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.”
Once users allowed access to their photo libraries, the malware scanned for wallet recovery phrases and other sensitive information, subsequently uploading this data to servers controlled by the attackers.
On iOS, SparkKitty was distributed via a cryptocurrency app named "币coin" found on Apple's App Store. According to Check Point, this app masked its malicious code to bypass Apple's review process before seeking access to users' photo libraries. For Android, the malware was present in a messaging and cryptocurrency exchange application called SOEX, which had over 10,000 downloads from Google Play before its removal. Other variants appeared in third-party app stores, counterfeit TikTok applications, gambling apps, and sideloaded APKs.
Unlike many other information-stealing malware that depend on clipboard monitoring or keylogging, SparkKitty directly searched users' photo libraries, making screenshots of wallet recovery phrases a key target.
Experts advise keeping wallet recovery phrases offline instead of as screenshots, restricting photo library permissions to trusted applications, and downloading software solely from reputable developers.
This report comes amid a series of malware campaigns aimed at cryptocurrency users. In March, Google revealed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet applications while stealing messages, passwords, photos, and other data from vulnerable iPhones. Additionally, the FBI initiated an investigation after malware was discovered in several games distributed via Valve's Steam platform, including titles like “Chemia,” “PirateFi,” and “Tokenova.”
In May, AI startup Perplexity released Bumblebee, a security tool designed to identify compromised software packages, browser extensions, and AI connector configurations without executing potentially harmful code following a software supply-chain attack that impacted over 160 developer packages.
In June, Kaspersky reported that attackers had been using Steam Workshop to spread malicious downloads disguised as anime-themed desktop wallpapers. This campaign deployed Lumma and Vidar infostealers, malware often utilized to steal browser credentials and cryptocurrency wallet information.
