On July 27, Check Point disclosed that a cross-platform malware strain called SparkKitty had spread through Apple’s App Store, Google Play, and third-party Android app stores, with crypto wallet seed phrases, passwords, and QR codes among its targets.
According to the report, SparkKitty uses OCR, or optical character recognition, to scan images in a user’s photo library for sensitive wallet-related information. Check Point said the malware is an upgraded version of the earlier infostealer SparkCat and has been distributed through apps posing as crypto services, messaging tools, and entertainment platforms.
How the malware works
After installation, the infected app asks for access to the user’s photo library and continues scanning both existing and newly added images. Text extracted from those images is then uploaded to an attacker-controlled server together with device information.
Check Point said that if a user stores a wallet seed phrase as a screenshot or photo, theft of that image can give an attacker full control of the corresponding crypto wallet.
Samples found on iOS and Android
On iOS, the malicious code was embedded in a crypto application called “币 coin,” and the report said code obfuscation helped it get past Apple’s review process.
On Android, researchers found the malware in a chat and crypto trading app called “SOEX.” The app was removed from Google Play only after its cumulative downloads had exceeded 10,000.
Distribution channels and security advice
Beyond official app stores, the attackers also distributed SparkKitty through third-party app stores, sideloaded APKs, modified TikTok versions, and entertainment apps.
The security firm advised users not to store wallet seed phrases in a phone’s photo gallery and instead keep them offline, such as on paper backups or hardware wallet backups. It also recommended being cautious when granting photo access permissions and downloading apps only from trusted sources.

