In short
- SparkKitty scanned customers’ picture libraries for crypto pockets seed phrases and different delicate info.
- The malware was distributed by means of malicious apps on Apple’s App Retailer, Google Play, and third-party app shops.
- Researchers warn that storing pockets restoration phrases as screenshots can expose crypto belongings to theft.
A brand new report from cybersecurity agency Examine Level particulars how the SparkKitty malware marketing campaign focused cryptocurrency customers by scanning pictures saved on contaminated Android and iPhone units for pockets restoration phrases and different delicate info.
First found by Kaspersky in June 2025, Examine Level’s evaluation detailed how the malware unfold by means of Apple’s App Retailer, Google Play, and third-party app shops.
“What makes SparkKitty notably notable is its presence on each the Apple App Retailer and Google Play, giving it a large assault floor,” Examine Level wrote. “The menace actor behind SparkKitty distributed trojanized functions disguised as official cryptocurrency instruments, messaging platforms, and even leisure apps—tremendously growing the chance of set up by unsuspecting customers.”
After customers granted entry to their picture libraries, the malware scanned saved photos for pockets restoration phrases and different delicate info earlier than importing the info to attacker-controlled servers.
On iOS, SparkKitty was distributed by means of a cryptocurrency app known as “币coin” that was out there on Apple’s App Retailer. Examine Level stated the app hid its malicious code to evade Apple’s overview course of earlier than requesting entry to customers’ picture libraries. On Android, the malware appeared in a messaging and cryptocurrency alternate app known as SOEX, which was downloaded greater than 10,000 instances from Google Play earlier than being eliminated. Different variants had been distributed by means of third-party app shops, pretend TikTok apps, playing apps, and sideloaded APKs.
Not like many info stealers that depend on clipboard monitoring or keylogging, SparkKitty searched customers’ picture libraries instantly, making screenshots of pockets restoration phrases a first-rate goal.
Researchers advocate retaining pockets restoration phrases offline as an alternative of storing them as screenshots, limiting picture library permissions to trusted apps, and downloading software program solely from respected builders.
The report follows a string of malware campaigns concentrating on cryptocurrency customers. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware able to concentrating on main cryptocurrency exchanges and pockets apps whereas stealing messages, passwords, pictures, and different information from weak iPhones. That very same month, the FBI launched an investigation after a number of video games distributed by means of Valve’s Steam platform—together with “Chemia,” “PirateFi,” and “Tokenova”—had been discovered to put in malware.
In Might, AI startup Perplexity open-sourced Bumblebee, a safety software designed to detect compromised software program packages, browser extensions, and AI connector configurations with out executing doubtlessly malicious code following a software program supply-chain assault that affected greater than 160 developer packages.
In June, Kaspersky reported that attackers had been utilizing Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. The marketing campaign deployed Lumma and Vidar infostealers, malware generally used to steal browser credentials and cryptocurrency pockets information.
Every day Debrief Publication
Begin each day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.

