Key facts
- SparkKitty malware scanned users' photo libraries for crypto wallet seed phrases and sensitive information.
- The malware was distributed through malicious apps on Apple's App Store, Google Play, and third-party app stores.
The SparkKitty malware campaign targeted cryptocurrency users by scanning photo libraries on infected Android and iOS devices for wallet recovery phrases and sensitive information. Distributed through malicious apps on Apple's App Store, Google Play, and third-party stores, it uploaded stolen data to attacker-controlled servers.

This campaign highlights the persistent threat of malware targeting cryptocurrency users, emphasizing the risks associated with storing sensitive recovery information insecurely, such as in screenshots, and the importance of vigilance regarding app permissions and download sources.
The SparkKitty malware campaign targeted cryptocurrency users by scanning photo libraries on infected Android and iOS devices for wallet recovery phrases and sensitive information. Distributed through malicious apps on Apple's App Store, Google Play, and third-party stores, it uploaded stolen data to attacker-controlled servers.
First discovered by Kaspersky in June 2025, Check Point's analysis detailed how the malware spread through Apple's App Store, Google Play, and third-party app stores. The threat actor disguised trojanized applications as legitimate cryptocurrency tools, messaging platforms, and entertainment apps to increase the likelihood of installation.
After users granted access to their photo libraries, SparkKitty scanned stored images for wallet recovery phrases and other sensitive information before uploading the data. On iOS, the malware was distributed through a cryptocurrency app called '币coin' on Apple's App Store, which concealed its malicious code to evade review. On Android, the malware appeared in a messaging and cryptocurrency exchange app called SOEX, downloaded over 10,000 times from Google Play before removal. Other variants were distributed through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs.
Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users' photo libraries directly, making screenshots of wallet recovery phrases a prime target. Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers.