SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases

Summary

SparkKitty is a malware campaign targeting cryptocurrency users by abusing photo-library access on infected Android and iPhone devices. It spread through the Apple App Store, Google Play, third-party app stores, and sideloaded APKs by posing as legitimate crypto, messaging, gambling, and entertainment apps. Once installed and granted photo access, it scanned stored images for wallet recovery phrases and other sensitive data, then sent the findings to attacker-controlled servers. On iOS, it was hidden inside a crypto app called 币coin; on Android, it appeared in the SOEX messaging/exchange app, which reached over 10,000 downloads before removal. Unlike clipboard- or keyboard-based stealers, SparkKitty directly searched photo libraries, making screenshots of recovery phrases especially risky. Recommended defenses include keeping recovery phrases offline, limiting photo permissions, and downloading apps only from trusted developers.