SparkKitty malware slipped into Apple and Google app stores to steal crypto wallet seed phrases

SparkKitty malware slipped into Apple and Google app stores to steal crypto wallet seed phrases

N
News Editor
2026-07-27 11:37:13
Security firm Check Point said on July 27 that a cross-platform malware strain called SparkKitty has been distributed through Apple’s App Store, Google Play, and third-party Android app stores. The malware uses optical character recognition, or OCR, to scan images stored in a user’s photo library for crypto wallet seed phrases, passwords, and QR codes. Once installed, the app requests access to photos, keeps scanning both existing and newly added images, and uploads extracted text along with device information to an attacker-controlled server. Check Point described SparkKitty as an upgraded version of the earlier infostealer SparkCat. On iOS, malicious code was found inside a crypto app called “币 coin,” which reportedly used code obfuscation to pass Apple’s review process. On Android, researchers said a chat and crypto trading app called “SOEX” carried the malware and was removed from Google Play only after surpassing 10,000 downloads. The report also said the malware spread through third-party app stores, sideloaded APKs, modified TikTok versions, and entertainment apps. Check Point warned users not to store seed phrases in phone photo galleries and recommended offline backups instead.
SparkKittymalwarecrypto walletsseed phrasesApp StoreGoogle PlayCheck Point

On July 27, Check Point disclosed that a cross-platform malware strain called SparkKitty had spread through Apple’s App Store, Google Play, and third-party Android app stores, with crypto wallet seed phrases, passwords, and QR codes among its targets.

According to the report, SparkKitty uses OCR, or optical character recognition, to scan images in a user’s photo library for sensitive wallet-related information. Check Point said the malware is an upgraded version of the earlier infostealer SparkCat and has been distributed through apps posing as crypto services, messaging tools, and entertainment platforms.

How the malware works

After installation, the infected app asks for access to the user’s photo library and continues scanning both existing and newly added images. Text extracted from those images is then uploaded to an attacker-controlled server together with device information.

Check Point said that if a user stores a wallet seed phrase as a screenshot or photo, theft of that image can give an attacker full control of the corresponding crypto wallet.

Samples found on iOS and Android

On iOS, the malicious code was embedded in a crypto application called “币 coin,” and the report said code obfuscation helped it get past Apple’s review process.

On Android, researchers found the malware in a chat and crypto trading app called “SOEX.” The app was removed from Google Play only after its cumulative downloads had exceeded 10,000.

Distribution channels and security advice

Beyond official app stores, the attackers also distributed SparkKitty through third-party app stores, sideloaded APKs, modified TikTok versions, and entertainment apps.

The security firm advised users not to store wallet seed phrases in a phone’s photo gallery and instead keep them offline, such as on paper backups or hardware wallet backups. It also recommended being cautious when granting photo access permissions and downloading apps only from trusted sources.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.