SparkKitty malware found scanning photos for crypto seed phrases
Security & Exploits ·
A cybersecurity firm's new report shows malicious apps on Apple's App Store and Google Play harvested images from infected phones in search of wallet recovery phrases.
Cybersecurity firm Check Point published an analysis of a malware campaign called SparkKitty, which spread across Android and iPhone devices by hiding inside apps that appeared legitimate, according to Decrypt. The malware was first identified by Kaspersky in June 2025, and Check Point's follow-up traced its distribution to Apple's App Store, Google Play, and unofficial third-party app stores.
Once installed, the apps requested access to a user's photo library and then combed through stored images for wallet recovery phrases and other sensitive data, sending anything found to servers controlled by the attackers, per The Block. On iOS, the malicious code was embedded in a cryptocurrency-themed app called "币coin," which reportedly disguised its behavior well enough to pass Apple's review process. On Android, it turned up in a messaging and exchange app named SOEX that had been installed more than 10,000 times before Google removed it from the Play Store. Additional versions were reportedly pushed through fake TikTok apps, gambling apps, and sideloaded Android packages.
The technique sets SparkKitty apart from more common crypto-targeting malware that relies on clipboard hijacking or keystroke logging; instead, it went straight after screenshots and saved images, betting that users who photograph or screenshot their seed phrases for safekeeping had effectively left them exposed. Researchers advised against storing recovery phrases as images at all, recommending offline storage, restricting photo-library permissions to trusted apps, and sourcing software only from established developers.
The discovery adds to a run of crypto-focused malware incidents flagged this year, including a Google-disclosed exploit chain in March that deployed spyware capable of pulling data from vulnerable iPhones, an FBI inquiry into infected games distributed on a gaming platform, and a June campaign that used disguised desktop wallpaper downloads to spread credential-stealing programs. Four separate sources have now reported on the SparkKitty findings, underscoring how photo-based seed phrase theft has become a recurring vector rather than an isolated case.
What remains unclear is the total number of devices compromised across both platforms beyond the confirmed download count for the Android app, and whether Apple's or Google's review processes will be adjusted specifically in response to how the malicious code evaded initial screening.