- Check Point published an analysis on Sunday of SparkKitty, a cross-platform stealer that reached Apple’s App Store and Google Play, then scanned users’ photo libraries for wallet recovery phrases.
- The malware is not new: Check Point credits Kaspersky with discovering it in early 2024 and detailing it publicly in June 2025, and describes it as a direct evolution of the SparkCat stealer.
- It shipped inside the iOS app 币coin and the Android app SOEX, which passed 10,000 downloads on Google Play before removal; neither vendor has published a victim count or a loss figure.
SparkKitty, a mobile information stealer that reached Apple’s App Store and Google Play, requested access to users’ photo libraries and used optical character recognition to scan stored images for cryptocurrency wallet recovery phrases.
According to Check Point and Kaspersky, which first identified the malware in 2025, SparkKitty is a direct evolution of SparkCat, an earlier information stealer that had been scanning image galleries since at least March 2024.
Read more: Crypto Derivatives Pioneer BitMEX to Shut Down After Strategic Review
How It Worked
On iOS, the payload sat inside a cryptocurrency app called 币coin, published on the App Store, which hid its functionality inside obfuscated frameworks to get past Apple’s review.
Check Point said it remains unclear whether that developer account was compromised or complicit. Likewise, the Android version arrived in SOEX, an app presented as a messenger with cryptocurrency exchange features, which passed 10,000 downloads on Google Play before it was pulled.
Variants also spread through third-party stores and sideloaded installers, including modified TikTok clones and gambling apps, and used Xposed framework modules to persist on rooted devices.
Once granted gallery access, SparkKitty monitored the image directory and periodically scanned its contents with built-in text-recognition libraries, hunting for readable text in screenshots: recovery phrases, passwords and QR codes.
Whatever it found went to a command-and-control server along with device identifiers. Both official-store apps have been removed, and the indicator list Check Point published carries entries dated June 2025 alongside newer ones from April 2026.
“The attackers may later try to find various confidential data in the images, for instance, crypto wallet recovery phrases to access the victims’ assets,” Kaspersky researcher Dmitry Kalinin said when the malware was disclosed. Kaspersky colleague Sergey Puzan said an infected build of TikTok also embedded links to a suspicious store in the victim’s profile during sign-in.
Check Point mapped the campaign to techniques including delivering a malicious app through an authorised app store and collecting stored application data.
A further SparkCat variant turned up in iOS and Android apps in April 2026, going after the same recovery-phrase images. CNA has previously reported on clipboard-hijacking malware and on phishing campaigns that pursue the same 12 words by asking for them outright.
Read more: South Korea’s Crypto Trading Slumps as Investors Pile Into Booming Stock Market





Be the first to comment