Kaspersky researchers uncovered SparkKitty, a Trojan malware that scans user photo galleries to extract screenshots containing crypto wallet seed phrases using optical character recognition technology. The malware was found in the BiCoin app on Apple’s App Store and the SOEX app on Google Play, accumulating over 10,000 installs before removal. Active since at least February 2024, it operated undetected for over a year and is linked to the SparkCat operation reported in January 2025. The campaign primarily targeted users in China and Southeast Asia. Kaspersky recommends immediately deleting any seed phrase screenshots and using hardware wallets for significant holdings.
Source: Read the original article

