SparkKitty malware snuck into App Store, photobombed crypto seed phrases 🐱
A malware campaign documented by cybersecurity firm Check Point reached users through Apple's App Store, Google Play, and several third-party stores, scanning infected Android and iPhone photo libraries for cryptocurrency wallet recovery phrases and other sensitive data. First identified by Kaspersky in June 2025, the SparkKitty operation distributed trojanized applications disguised as cryptocurrency tools, messaging platforms, and entertainment apps. "What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface," Check Point wrote. "The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users."
On iOS, SparkKitty was delivered through a cryptocurrency application called "币coin" listed on Apple's App Store. Check Point said the app concealed its malicious code to pass Apple's review process before requesting photo library access from users. On Android, the malware appeared inside a messaging and cryptocurrency exchange application named SOEX, which was downloaded more than 10,000 times from Google Play before removal. Additional variants spread through third-party app stores, counterfeit TikTok applications, gambling apps, and sideloaded APKs.
Rather than relying on clipboard monitoring or keylogging like many information stealers, SparkKitty searched stored images directly, making screenshots of wallet recovery phrases a primary target. Researchers advise keeping recovery phrases offline instead of saving them as images, restricting photo library permissions to trusted applications, and downloading software only from reputable developers.
The report arrives alongside other recent campaigns aimed at cryptocurrency users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet applications while extracting messages, passwords, photos, and other data from vulnerable iPhones. That same month, the FBI opened an investigation after games distributed through Valve's Steam platform, including "Chemia," "PirateFi," and "Tokenova," were found to install malware. In May, AI startup Perplexity open-sourced Bumblebee, a security tool designed to detect compromised software packages, browser extensions, and AI connector configurations without executing potentially malicious code, following a software supply-chain attack that affected more than 160 developer packages. In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.