Skip to content
Data Breach

SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos

A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones. Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and gallery images. Instead of logging keystrokes...

· Jul 27, 2026 · 6 min read · 👁 0 views
SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos

A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones.

Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and gallery images.

Instead of logging keystrokes or watching the clipboard, it uses optical character recognition to pull text straight from pictures.

The campaign has already reached official app marketplaces, which means everyday users who trust those stores remain at risk.

Once installed, the malware asks for photo access, scans images for sensitive strings, and sends the results to remote servers controlled by the attackers.

Analysts or researchers from Check Point identified the malware and mapped how it spreads through trojanized apps that look like normal crypto tools, messaging platforms, and entertainment software.

Check Point said in a report shared with Cyber Security News (CSN) that SparkKitty is a direct evolution of an earlier stealer called SparkCat.

Related coverage of earlier malicious apps targeting mobile users shows how similar OCR-based theft has grown over time.

The impact is serious because a single leaked seed phrase can give criminals full control of a crypto wallet and empty it within minutes.

Victims may never notice anything wrong until funds disappear. The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.

Widespread availability through popular stores and third-party sideloading channels has expanded the pool of potential targets far beyond niche communities.

SparkKitty Malware Steals Crypto Wallet Seed Phrases

SparkKitty stands out because it treats the photo gallery as a treasure chest of financial secrets. Many people photograph or screenshot their recovery phrases for convenience, and the malware is built to find exactly those images.

After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.

On iOS the payload hid inside a cryptocurrency-themed app called “币coin” that appeared on the App Store. Obfuscated frameworks helped it slip past initial review.

On Android an app named “SOEX” posed as a messaging and exchange platform, gained more than 10,000 downloads on Google Play, and was later removed.

Variants also spread through third-party stores, modded TikTok clones, and gambling apps, echoing patterns seen when researchers examined malicious Android apps found on official marketplaces.

Extracted text, including seed phrases, passwords, and QR code data, travels silently to command-and-control infrastructure along with basic device metadata.

Users who keep recovery information in plain screenshots face the highest risk. The same approach can capture other secrets stored as images, turning a simple photo backup habit into a costly mistake for anyone holding digital assets.

How SparkKitty Reaches Mobile Devices

Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.

Both routes request gallery access soon after install so scanning can begin without further user interaction.

Security teams tracking Google Play malicious apps removal efforts note that even brief store presence can produce thousands of infections.

Once active, SparkKitty continues monitoring for new images, so later screenshots of wallets remain exposed. People who manage online crypto payment risks should treat any unexpected photo permission request as a warning sign.

Practical steps reduce exposure. Avoid installing crypto or messaging apps from unknown sources, deny gallery access unless it is essential, and never store seed phrases as photos or screenshots.

Prefer hardware wallets or offline paper backups kept in secure physical locations. Keep devices updated, review app permissions regularly, and remove any application that suddenly asks for broad media access.

If infection is suspected, disconnect from networks, move remaining funds from a clean device, and rotate related credentials promptly.

These habits close the main gaps SparkKitty exploits and help users stay ahead of similar photo-scanning stealers that may appear.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
MD57e678ca2f01dc853e85d13924e6c8a45SparkKitty sample hash
MD58d45a67b648d2cb46292ff5041a5dd44SparkKitty sample hash
MD579fe383f0963ae741193989c12aefaccSparkKitty sample hash
MD5bafba3d044a4f674fc9edc67ef6b8a6bSparkKitty sample hash
MD5d48b580718b0e1617afc1dec028e9059SparkKitty sample hash
MD5b639f7f81a8faca9c62fd227fef5e28cSparkKitty sample hash
MD54126348d783393dd85ede3468e48405dSparkKitty sample hash
MD5fe0868c4f40cbb42eb58af121570e64dSparkKitty sample hash
MD5fd4558a9b629b5abe65a649b57bef20cSparkKitty sample hash
MD5fa0e99bac48bc60aa0ae82bc0fd1698dSparkKitty sample hash
MD5f9ab4769b63a571107f2709b5b14e2bcSparkKitty sample hash
MD5f10a4fdffc884089ae93b0372ff9d5d1SparkKitty sample hash
MD5f0815908bafd88d71db660723b65fba4SparkKitty sample hash
MD5f0460bdca0f04d3bd4fc59d73b52233bSparkKitty sample hash
MD5ec068e0fc6ffda97685237d8ab8a0f56SparkKitty sample hash
MD5e9f7d9bc988e7569f999f0028b359720SparkKitty sample hash
MD5e8b60bf5af2d5cc5c501b87d04b8a6c2SparkKitty sample hash
MD5e5186be781f870377b6542b3cecfb622SparkKitty sample hash
MD5d851b19b5b587f202795e10b72ced6e1SparkKitty sample hash
MD5d4f42319a78b6605cabb5696bacb4677SparkKitty sample hash
MD5ce49a90c0a098e8737e266471d323626SparkKitty sample hash
MD5cc919d4bbd3fb2098d1aeb516f356ccaSparkKitty sample hash
MD5c6a7568134622007de026d22257502d5SparkKitty sample hash
MD5c5be3ae482d25c6537e08c888a742832SparkKitty sample hash
MD5b4489cb4fac743246f29abf7f605dd15SparkKitty sample hash
MD5b3085cd623b57fd6561e964d6fd73413SparkKitty sample hash
MD5b0eda03d7e4265fe280360397c042494SparkKitty sample hash
MD5b0976d46970314532bc118f522bb8a6fSparkKitty sample hash
MD5aa5ce6fed4f9d888cbf8d6d8d0cda07fSparkKitty sample hash
SHA-1f9182892299b52b2236fd98c1262e2f0837e1683SparkKitty sample hash
SHA-18a84ce9cbf239fc8a3e7e3ed0b4f0050b7113e92SparkKitty sample hash
SHA-15861f7d50d9000fd43ea1552164e7d1f850f0c9bSparkKitty sample hash
SHA-256cdbe32fcb10606846035fff7c2f54d1b4306ef08cSparkKitty sample hash
SHA-2569ca063d5716155d9e70ebda9370655c65dcf82bSparkKitty sample hash
SHA-2565b4d879862d8bd8af65a4151967990ef830b8c4SparkKitty sample hash
URLyjhjymfjnj.wyxbmh.cnCommand-and-control URL
URLxt.xinqianf38.topCommand-and-control URL
URLlt.laoqianf51.topCommand-and-control URL
URLlt.laoqianf15.topCommand-and-control URL
URLlt.laoqianf14.topCommand-and-control URL
URLi.bicoin.com.cnCommand-and-control URL
URLh1997.tiktokapp.clubCommand-and-control URL
URLapi.fxsdk.comCommand-and-control URL
Domainmoabc.vipMalicious domain
Domainbyteepic.vipMalicious domain
Domainaccgngrid.comMalicious domain
IPv447.119.171.161Command-and-control IP
IPv439.108.186.119Command-and-control IP
IPv423.249.28.88Command-and-control IP
IPv4120.79.8.107Command-and-control IP

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you