SparkKitty Malware Targets Crypto Seed Phrases Hidden in Phone Photos

SparkKitty Malware Targets Crypto Seed Phrases Hidden in Phone Photos

Last Updated:
SparkKitty Malware Targets Crypto Seed Phrases Hidden in Phone Photos
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • SparkKitty scans photos to steal crypto wallet recovery phrases with OCR.
  • Malicious apps carrying SparkKitty were listed on App Store and Google Play before removal. 
  • Researchers warned fake wallet apps can expose users’ recovery phrases.

A malware campaign, SparkKitty, has emerged as a security concern after researchers found malicious applications targeting crypto wallet recovery phrases stored in users’ photo libraries. The malware affected both iOS and Android devices through applications distributed on the Apple App Store and Google Play.

According to cybersecurity researchers, once users granted photo access, the malware scanned stored images for wallet recovery phrases using optical character recognition (OCR) before transmitting the extracted data to attacker-controlled servers.

SparkKitty Malware Relied on Photo Library Access

Researchers said the campaign functioned by exploiting a permission that many users routinely approve during app installation. Rather than attempting to capture passwords through traditional methods such as keystroke logging, SparkKitty focused on images already saved on infected devices.

Kaspersky, which documented the malware in June 2025, said SparkKitty evolved from the earlier SparkCat campaign. Once installed, the impacted applications requested access to a user’s photo library and continuously scanned both existing and newly saved images.

Using OCR technology, the malware searched specifically for 12-word and 24-word crypto wallet recovery phrases before forwarding the extracted information, along with basic device details, to attacker-controlled command-and-control servers.

Researchers Identified Malicious Applications

As investigators examined the attack further, they identified several applications carrying the malware on official app stores. Kaspersky cited the 币coin application and SOEX among the affected apps, with SOEX recording more than 10,000 downloads before its removal. 

Following alerts from researchers, both Apple and Google removed the identified applications from their respective app stores.

Check Point also examined the malware and concluded that SparkKitty shared the same OCR-based approach previously seen in SparkCat. The firm reported that the malware searched screenshots not only for cryptocurrency recovery phrases but also for passwords and QR code data stored in images.

The research findings were followed by public warnings from investor Evan Luthra, who highlighted how attackers combined malware with fraudulent wallet applications. He stated that researchers had also identified 26 fake wallet apps on the Apple App Store that replicated crypto wallets by using similar logos and slight spelling changes.

According to his statement, users who entered their recovery phrases into those applications could unknowingly hand their wallet credentials to attackers.

Related: Microsoft Flags Two Malicious npm Packages Targeting Crypto Wallets

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.