cognitive cybersecurity intelligence

News and Analysis

Search

SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos

SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos

A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones.

Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and gallery images.

Instead of logging keystrokes or watching the clipboard, it uses optical character recognition to pull text straight from pictures.

The campaign has already reached official app marketplaces, which means everyday users who trust those stores remain at risk.

Once installed, the malware asks for photo access, scans images for sensitive strings, and sends the results to remote servers controlled by the attackers.

Analysts or researchers from Check Point identified the malware and mapped how it spreads through trojanized apps that look like normal crypto tools, messaging platforms, and entertainment software.

Check Point said in a report shared with Cyber Security News (CSN) that SparkKitty is a direct evolution of an earlier stealer called SparkCat.

Related coverage of earlier malicious apps targeting mobile users shows how similar OCR-based theft has grown over time.

The impact is serious because a single leaked seed phrase can give criminals full control of a crypto wallet and empty it within minutes.

Victims may never notice anything wrong until funds disappear. The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.

Widespread availability through popular stores and third-party sideloading channels has expanded the pool of potential targets far beyond niche communities.

SparkKitty Malware Steals Crypto Wallet Seed Phrases

SparkKitty stands out because it treats the photo gallery as a treasure chest of financial secrets. Many people photograph or screenshot their recovery phrases for convenience, and the malware is built to find exactly those images.

After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.

On iOS the payload hid inside a cryptocurrency-themed app called “币coin” that appeared on the App Store. Obfuscated frameworks helped it slip past initial review.

On Android an app named “SOEX” posed as a messaging and exchange platform, gained more than 10,000 downloads on Google Play, and was later removed.

Variants also spread through third-party stores, modded TikTok clones, and gambling apps, echoing patterns seen when researchers examined malicious Android apps found on official marketplaces.

Extracted text, including seed phrases, passwords, and QR code data, travels silently to command-and-control infrastructure along with basic device metadata.

Users who keep recovery information in plain screenshots face the highest risk. The same approach can capture other secrets stored as images, turning a simple photo backup habit into a costly mistake for anyone holding digital assets.

How SparkKitty Reaches Mobile Devices

Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.

Both routes request gallery access soon after install so scanning can begin without further user interaction.

Security teams tracking Google Play malicious apps removal efforts note that even brief store presence can produce thousands of infections.

Once active, SparkKitty continues monitoring for new images, so later screenshots of wallets remain exposed. People who manage online crypto payment risks should treat any unexpected photo permission request as a warning sign.

Practical steps reduce exposure. Avoid installing crypto or messaging apps from unknown sources, deny gallery access unless it is essential, and never store seed phrases as photos or screenshots.

Prefer hardware wallets or offline paper backups kept in secure physical locations. Keep devices updated, review app permissions regularly, and remove any application that suddenly asks for broad media access.

If infection is suspected, disconnect from networks, move remaining funds from a clean device, and rotate related credentials promptly.

These habits close the main gaps SparkKitty exploits and help users stay ahead of similar photo-scanning stealers that may appear.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionMD57e678ca2f01dc853e85d13924e6c8a45SparkKitty sample hashMD58d45a67b648d2cb46292ff5041a5dd44SparkKitty sample hashMD579fe383f0963ae741193989c12aefaccSparkKitty sample hashMD5bafba3d044a4f674fc9edc67ef6b8a6bSparkKitty sample hashMD5d48b580718b0e1617afc1dec028e9059SparkKitty sample hashMD5b639f7f81a8faca9c62fd227fef5e28cSparkKitty sample hashMD54126348d783393dd85ede3468e48405dSparkKitty sample hashMD5fe0868c4f40cbb42eb58af121570e64dSparkKitty sample hashMD5fd4558a9b629b5abe65a649b57bef20cSparkKitty sample hashMD5fa0e99bac48bc60aa0ae82bc0fd1698dSparkKitty sample hashMD5f9ab4769b63a571107f2709b5b14e2bcSparkKitty sample hashMD5f10a4fdffc884089ae93b0372ff9d5d1SparkKitty sample hashMD5f0815908bafd88d71db660723b65fba4SparkKitty sample hashMD5f0460bdca0f04d3bd4fc59d73b52233bSparkKitty sample hashMD5ec068e0fc6ffda97685237d8ab8a0f56SparkKitty sample hashMD5e9f7d9bc988e7569f999f0028b359720SparkKitty sample hashMD5e8b60bf5af2d5cc5c501b87d04b8a6c2SparkKitty sample hashMD5e5186be781f870377b6542b3cecfb622SparkKitty sample hashMD5d851b19b5b587f202795e10b72ced6e1SparkKitty sample hashMD5d4f42319a78b6605cabb5696bacb4677SparkKitty sample hashMD5ce49a90c0a098e8737e266471d323626SparkKitty sample hashMD5cc919d4bbd3fb2098d1aeb516f356ccaSparkKitty sample hashMD5c6a7568134622007de026d22257502d5SparkKitty sample hashMD5c5be3ae482d25c6537e08c888a742832SparkKitty sample hashMD5b4489cb4fac743246f29abf7f605dd15SparkKitty sample hashMD5b3085cd623b57fd6561e964d6fd73413SparkKitty sample hashMD5b0eda03d7e4265fe280360397c042494SparkKitty sample hashMD5b0976d46970314532bc118f522bb8a6fSparkKitty sample hashMD5aa5ce6fed4f9d888cbf8d6d8d0cda07fSparkKitty sample hashSHA-1f9182892299b52b2236fd98c1262e2f0837e1683SparkKitty sample hashSHA-18a84ce9cbf239fc8a3e7e3ed0b4f0050b7113e92SparkKitty sample hashSHA-15861f7d50d9000fd43ea1552164e7d1f850f0c9bSparkKitty sample hashSHA-256cdbe32fcb10606846035fff7c2f54d1b4306ef08cSparkKitty sample hashSHA-2569ca063d5716155d9e70ebda9370655c65dcf82bSparkKitty sample hashSHA-2565b4d879862d8bd8af65a4151967990ef830b8c4SparkKitty sample hashURLyjhjymfjnj.wyxbmh.cnCommand-and-control URLURLxt.xinqianf38.topCommand-and-control URLURLlt.laoqianf51.topCommand-and-control URLURLlt.laoqianf15.topCommand-and-control URLURLlt.laoqianf14.topCommand-and-control URLURLi.bicoin.com.cnCommand-and-control URLURLh1997.tiktokapp.clubCommand-and-control URLURLapi.fxsdk.comCommand-and-control URLDomainmoabc.vipMalicious domainDomainbyteepic.vipMalicious domainDomainaccgngrid.comMalicious domainIPv447.119.171.161Command-and-control IPIPv439.108.186.119Command-and-control IPIPv423.249.28.88Command-and-control IPIPv4120.79.8.107Command-and-control IP

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts