SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos
A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones.
Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and gallery images.
Instead of logging keystrokes or watching the clipboard, it uses optical character recognition to pull text straight from pictures.
The campaign has already reached official app marketplaces, which means everyday users who trust those stores remain at risk.
Once installed, the malware asks for photo access, scans images for sensitive strings, and sends the results to remote servers controlled by the attackers.
Analysts or researchers from Check Point identified the malware and mapped how it spreads through trojanized apps that look like normal crypto tools, messaging platforms, and entertainment software.
Check Point said in a report shared with Cyber Security News (CSN) that SparkKitty is a direct evolution of an earlier stealer called SparkCat.
Related coverage of earlier malicious apps targeting mobile users shows how similar OCR-based theft has grown over time.
The impact is serious because a single leaked seed phrase can give criminals full control of a crypto wallet and empty it within minutes.
Victims may never notice anything wrong until funds disappear. The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.
Widespread availability through popular stores and third-party sideloading channels has expanded the pool of potential targets far beyond niche communities.
SparkKitty Malware Steals Crypto Wallet Seed Phrases
SparkKitty stands out because it treats the photo gallery as a treasure chest of financial secrets. Many people photograph or screenshot their recovery phrases for convenience, and the malware is built to find exactly those images.
After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.
On iOS the payload hid inside a cryptocurrency-themed app called “币coin” that appeared on the App Store. Obfuscated frameworks helped it slip past initial review.
On Android an app named “SOEX” posed as a messaging and exchange platform, gained more than 10,000 downloads on Google Play, and was later removed.
Variants also spread through third-party stores, modded TikTok clones, and gambling apps, echoing patterns seen when researchers examined malicious Android apps found on official marketplaces.
Extracted text, including seed phrases, passwords, and QR code data, travels silently to command-and-control infrastructure along with basic device metadata.
Users who keep recovery information in plain screenshots face the highest risk. The same approach can capture other secrets stored as images, turning a simple photo backup habit into a costly mistake for anyone holding digital assets.
How SparkKitty Reaches Mobile Devices
Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.
Both routes request gallery access soon after install so scanning can begin without further user interaction.
Security teams tracking Google Play malicious apps removal efforts note that even brief store presence can produce thousands of infections.
Once active, SparkKitty continues monitoring for new images, so later screenshots of wallets remain exposed. People who manage online crypto payment risks should treat any unexpected photo permission request as a warning sign.
Practical steps reduce exposure. Avoid installing crypto or messaging apps from unknown sources, deny gallery access unless it is essential, and never store seed phrases as photos or screenshots.
Prefer hardware wallets or offline paper backups kept in secure physical locations. Keep devices updated, review app permissions regularly, and remove any application that suddenly asks for broad media access.
If infection is suspected, disconnect from networks, move remaining funds from a clean device, and rotate related credentials promptly.
These habits close the main gaps SparkKitty exploits and help users stay ahead of similar photo-scanning stealers that may appear.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 | 7e678ca2f01dc853e85d13924e6c8a45 | SparkKitty sample hash |
| MD5 | 8d45a67b648d2cb46292ff5041a5dd44 | SparkKitty sample hash |
| MD5 | 79fe383f0963ae741193989c12aefacc | SparkKitty sample hash |
| MD5 | bafba3d044a4f674fc9edc67ef6b8a6b | SparkKitty sample hash |
| MD5 | d48b580718b0e1617afc1dec028e9059 | SparkKitty sample hash |
| MD5 | b639f7f81a8faca9c62fd227fef5e28c | SparkKitty sample hash |
| MD5 | 4126348d783393dd85ede3468e48405d | SparkKitty sample hash |
| MD5 | fe0868c4f40cbb42eb58af121570e64d | SparkKitty sample hash |
| MD5 | fd4558a9b629b5abe65a649b57bef20c | SparkKitty sample hash |
| MD5 | fa0e99bac48bc60aa0ae82bc0fd1698d | SparkKitty sample hash |
| MD5 | f9ab4769b63a571107f2709b5b14e2bc | SparkKitty sample hash |
| MD5 | f10a4fdffc884089ae93b0372ff9d5d1 | SparkKitty sample hash |
| MD5 | f0815908bafd88d71db660723b65fba4 | SparkKitty sample hash |
| MD5 | f0460bdca0f04d3bd4fc59d73b52233b | SparkKitty sample hash |
| MD5 | ec068e0fc6ffda97685237d8ab8a0f56 | SparkKitty sample hash |
| MD5 | e9f7d9bc988e7569f999f0028b359720 | SparkKitty sample hash |
| MD5 | e8b60bf5af2d5cc5c501b87d04b8a6c2 | SparkKitty sample hash |
| MD5 | e5186be781f870377b6542b3cecfb622 | SparkKitty sample hash |
| MD5 | d851b19b5b587f202795e10b72ced6e1 | SparkKitty sample hash |
| MD5 | d4f42319a78b6605cabb5696bacb4677 | SparkKitty sample hash |
| MD5 | ce49a90c0a098e8737e266471d323626 | SparkKitty sample hash |
| MD5 | cc919d4bbd3fb2098d1aeb516f356cca | SparkKitty sample hash |
| MD5 | c6a7568134622007de026d22257502d5 | SparkKitty sample hash |
| MD5 | c5be3ae482d25c6537e08c888a742832 | SparkKitty sample hash |
| MD5 | b4489cb4fac743246f29abf7f605dd15 | SparkKitty sample hash |
| MD5 | b3085cd623b57fd6561e964d6fd73413 | SparkKitty sample hash |
| MD5 | b0eda03d7e4265fe280360397c042494 | SparkKitty sample hash |
| MD5 | b0976d46970314532bc118f522bb8a6f | SparkKitty sample hash |
| MD5 | aa5ce6fed4f9d888cbf8d6d8d0cda07f | SparkKitty sample hash |
| SHA-1 | f9182892299b52b2236fd98c1262e2f0837e1683 | SparkKitty sample hash |
| SHA-1 | 8a84ce9cbf239fc8a3e7e3ed0b4f0050b7113e92 | SparkKitty sample hash |
| SHA-1 | 5861f7d50d9000fd43ea1552164e7d1f850f0c9b | SparkKitty sample hash |
| SHA-256 | cdbe32fcb10606846035fff7c2f54d1b4306ef08c | SparkKitty sample hash |
| SHA-256 | 9ca063d5716155d9e70ebda9370655c65dcf82b | SparkKitty sample hash |
| SHA-256 | 5b4d879862d8bd8af65a4151967990ef830b8c4 | SparkKitty sample hash |
| URL | yjhjymfjnj.wyxbmh.cn | Command-and-control URL |
| URL | xt.xinqianf38.top | Command-and-control URL |
| URL | lt.laoqianf51.top | Command-and-control URL |
| URL | lt.laoqianf15.top | Command-and-control URL |
| URL | lt.laoqianf14.top | Command-and-control URL |
| URL | i.bicoin.com.cn | Command-and-control URL |
| URL | h1997.tiktokapp.club | Command-and-control URL |
| URL | api.fxsdk.com | Command-and-control URL |
| Domain | moabc.vip | Malicious domain |
| Domain | byteepic.vip | Malicious domain |
| Domain | accgngrid.com | Malicious domain |
| IPv4 | 47.119.171.161 | Command-and-control IP |
| IPv4 | 39.108.186.119 | Command-and-control IP |
| IPv4 | 23.249.28.88 | Command-and-control IP |
| IPv4 | 120.79.8.107 | Command-and-control IP |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos appeared first on Cyber Security News.
Tushar Subhra Dutta
Go to cyber-security-news