SparkKitty malware infiltrates App Store and Google Play to steal crypto seed phrases from photos

3 hours ago 15

Here’s a nightmare scenario most crypto holders haven’t considered: that screenshot of your seed phrase you took “just in case” is exactly what a new strain of malware is hunting for.

Kaspersky researchers on June 23 published findings on SparkKitty, a mobile spyware Trojan that has been quietly embedded inside apps distributed through both the Apple App Store and Google Play. The malware rifles through users’ photo galleries, applies optical character recognition technology to identify screenshots containing crypto wallet seed phrases, and uploads them to attacker-controlled servers.

How SparkKitty works

The Trojan uses OCR, the same technology that lets your phone scan documents, to read text within images. It specifically hunts for patterns that match seed phrase formats. Once it finds a match, the image gets exfiltrated to servers controlled by the attackers, who can then reconstruct the wallet and drain its contents.

On iOS, the malware disguised itself using fake frameworks designed to mimic legitimate networking libraries like AFNetworking and Alamofire. On Android, it leveraged malicious enterprise provisioning profiles to sideload itself onto devices.

According to Kaspersky’s research, the malware has been active since at least February 2024, meaning it operated undetected for well over a year before being publicly identified. It’s linked to the SparkCat operation that Kaspersky first reported in January 2025, suggesting this is an ongoing, evolving campaign rather than a one-off attack.

Which apps were infected

On the Apple App Store, the malware was embedded within an app called 币coin, a crypto-rate tracking application. On Google Play, it was found inside SOEX, a messaging app that incorporated crypto-exchange functionality and had accumulated over 10,000 installs before being pulled.

Beyond official app stores, SparkKitty also spread through unauthorized distribution channels, including modified versions of TikTok. The primary targets were users in China and Southeast Asia.

Both Apple and Google removed the infected applications following Kaspersky’s disclosure.

The bigger picture for crypto security

A seed phrase is the master key to a crypto wallet. Anyone who possesses it can access every asset stored within. Unlike a compromised password, there’s no “reset” option. Once someone has your seed phrase, your funds are gone, and blockchain transactions are irreversible.

The crypto market itself hasn’t reacted to the news. There’s been no visible price impact or increased on-chain activity suggesting mass wallet compromises. Kaspersky’s findings suggest the campaign was relatively targeted rather than broadly deployed.

For investors, the practical takeaway is operational security hygiene. Delete any screenshots of seed phrases immediately. Use a hardware wallet for significant holdings. Be skeptical of app permissions, particularly requests for photo gallery access from apps that have no business viewing your photos. A crypto price tracker has no legitimate reason to scan your camera roll.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article