SparkKitty: Inside the App Store Malware Scanning Your Gallery for Crypto Seed Phrases

Share

SparkKitty has just delivered a devastating blow to the trust placed in official app stores. This malware, identified by Kaspersky researchers in June 2025, operated for over a year — since February 2024 — inside seemingly legitimate applications on Apple’s App Store and Google Play. Its objective: to extract cryptocurrency wallet seed phrases stored as screenshots in victims’ photo galleries. A comprehensive look at a threat that redefines mobile cybercrime standards.

🔑 Key Takeaways

  • SparkKitty infiltrated the App Store (app « coin ») and Google Play (app « SOEX ») with over 10,000 downloads combined
  • The malware uses optical character recognition (OCR) to detect seed phrases in screenshots
  • Blockchain transactions are irreversible — once seed phrases are stolen, funds are permanently lost
  • The FBI received over 69,000 cryptocurrency fraud complaints in 2023, a 45 percent increase year over year

What Is SparkKitty?

SparkKitty is a cross-platform mobile spyware Trojan designed to infiltrate Android and iOS devices and systematically steal images from the victim’s photo gallery. Its primary objective is to identify, extract, and exfiltrate screenshots containing cryptocurrency wallet seed phrases — the master keys that grant full access to digital asset portfolios.

What makes SparkKitty particularly alarming is its reach. This malware does not rely exclusively on shady third-party APK downloads or unofficial app stores. It found its way into the two most heavily guarded mobile app marketplaces on the planet: Apple’s App Store and Google Play. That alone should raise serious concerns from every smartphone user who has ever taken a screenshot for safekeeping.

SparkKitty is not an entirely new creation. Researchers quickly identified it as a direct successor to another malware family called SparkCat, documented by Kaspersky in February 2025. Both families share code patterns, infrastructure, and tactics. But SparkKitty refines and amplifies its predecessor’s approach, making it more aggressive and more difficult to detect.

The Threat Posed by Seed Phrase Storage

To understand why this malware is so dangerous, it helps to understand what a seed phrase is and why it matters.

A cryptocurrency wallet seed phrase — also known as a recovery phrase or mnemonic phrase — is typically a sequence of 12 to 24 words generated when a user creates a crypto wallet. This phrase is essentially the master password for the entire wallet. Anyone who possesses it can reconstruct the wallet on any device and immediately gain access to all stored funds.

Unlike a compromised bank password, there is no customer support line to call, no fraud department to dispute the transaction, and no way to reverse a blockchain transfer once it is confirmed. This permanence is one of the core philosophical pillars of decentralized cryptocurrency. It is also, as SparkKitty demonstrates, one of its most exploitable weaknesses.

« Because blockchain transactions are irreversible, the victim has no recourse once funds are drained. The malware transforms a security instinct into a critical vulnerability. »

Kaspersky, Securelist, June 2025

How SparkKitty Infiltrated Official App Stores

The fact that SparkKitty reached both major app stores is one of the most troubling aspects of this campaign. Apple’s App Store has long been considered a fortress — apps undergo rigorous review before being published, and Apple’s closed ecosystem makes sideloading difficult. Google Play, while more permissive, still has substantial security filters.

In Apple’s App Store, the malware was hiding inside an app called « coin », marketed as a cryptocurrency rate tracking and trading signal application. It looked entirely legitimate. The app functioned as advertised, which helped it build positive reviews and user trust. Hidden within its code, however, was a malicious framework that mimicked legitimate networking libraries such as AFNetworking and Alamofire.

On Google Play, the infected app was called SOEX — a messaging application that also incorporated cryptocurrency exchange features. It had accumulated over 10,000 downloads before being removed.

ApplicationStoreMalware NameEst. DownloadsStatus
coinApple App StoreSparkKittyNot disclosedRemoved
SOEXGoogle PlaySparkKitty10,000+Removed
Modified TikTokUnofficial sourcesSparkKittyUnknownActive (parallel channels)

Beyond Official App Stores

SparkKitty did not limit itself to official marketplaces. Researchers also discovered the malware being distributed through unofficial channels, including modified versions of the TikTok app. These trojanized versions were promoted through suspicious links and third-party stores, particularly targeting users in China and Southeast Asia.

On Android, some versions of SparkKitty integrated with the Xposed framework — a powerful tool for customizing Android system behavior — to gain advanced persistence on rooted devices. For iOS devices, attackers exploited Apple’s enterprise provisioning profile system to get users to install modified versions of TikTok with malicious functionality embedded inside.

Technical Breakdown: How the Malware Works

Once installed and granted access to the photo gallery, SparkKitty begins its work systematically. The malware continuously monitors the gallery, scanning both existing images and newly added ones. Several variants incorporate OCR engines — often based on Google ML Kit, the same technology that powers legitimate document scanning on smartphones — to detect and extract text from screenshots.

The recognized text is then evaluated against attacker-defined rulesets. These rulesets are designed to flag patterns consistent with cryptocurrency wallet seed phrases, recovery words, backup codes, and other sensitive financial data. In some configurations, SparkKitty uploads every single image from the gallery along with device metadata — model, operating system version, locale, and installed app identifiers — providing operators with rich material for victim profiling.

« This mass exfiltration approach marks a shift from SparkCat, which was more selective. SparkKitty takes a scorched-earth approach. Even if a photo is not immediately useful, it could contain personal information enabling follow-on fraud or, in extreme cases, blackmail campaigns. »

Kaspersky GReAT Team, June 2025

Geographic Scope and Victim Profile

SparkKitty’s operators appear to be primarily targeting users in China and Southeast Asia, with a particular focus on individuals who are active in cryptocurrency trading and use mobile wallets and exchanges. The keywords flagged by the malware’s OCR engine include terms in Chinese, Japanese, Korean, English, Czech, French, Italian, Polish, and Portuguese — a broad multilingual sweep covering major financial markets across Asia and Europe.

The campaign’s infrastructure tells the same story. Command-and-control domains identified by researchers include addresses such as yjhjymfjnj.wyxbmh.cn, xt.xinqianf38.top, lt.laoqianf51.top, and lt.laoqianf14.top, many of which have been previously associated with cryptocurrency and Ponzi scam operations.

The Broader Context: Mobile Malware Is Exploding

SparkKitty is not an isolated incident. It is part of a broader, alarming surge in smartphone-focused cyberattacks. According to Statista data, mobile devices accounted for 83 percent of all malware strains between 2021 and 2023, with attacks increasing globally by 8 percent year over year. The combination of increasingly sophisticated mobile malware and the irreversible nature of cryptocurrency transactions creates an environment where victims can lose everything in minutes.

YearFBI Complaints (crypto fraud)Year-over-Year ChangeEstimated Losses
2022~47,600~$3.9 billion USD
202369,000++45%$5.6 billion USD

The numbers from the FBI underscore the scale of the problem. In 2023 alone, the agency’s Internet Crime Complaint Center received over 69,000 complaints related to cryptocurrency fraud — a 45 percent increase from the previous year — reflecting more than $5.6 billion in losses. And those are only the reported cases.

How to Protect Yourself

The emergence of SparkKitty inside official app stores is a wake-up call. The old advice — only download from trusted sources — is no longer sufficient on its own, because trusted sources can be compromised. Here are the concrete steps every cryptocurrency holder should take immediately.

Go through your screenshots and delete any that contain seed phrases, private keys, wallet addresses, passwords, or any other sensitive financial information. Do not rely on the trash folder either — permanently delete them. If you need to keep a record of your seed phrase, write it down on paper and store it in a secure physical location, such as a safe.

Use an Encrypted Vault

Kaspersky Password Manager, among other solutions, offers encrypted photo storage where files can only be accessed after entering a master password known only to the user. Protected content syncs across devices, meaning you can access important files without leaving them exposed in an unencrypted gallery.

Scrutinize App Permissions

If a cryptocurrency price tracker, a messaging app, or any application that has no obvious reason to view your photos requests gallery access, deny that request and consider uninstalling the app. A crypto portfolio tracker has no legitimate business scanning your camera roll.

Consider a Hardware Wallet

For significant holdings, consider a hardware wallet. These devices store private keys offline, meaning seed phrases never touch an internet-connected device at all. This eliminates the attack surface entirely for malware of this type.

Keep Your OS Updated

Keep your phone’s operating system updated. Security patches in iOS and Android updates frequently address vulnerabilities that malware like SparkKitty exploits.


Conclusion: Convenience vs. Security

SparkKitty exploits a very human instinct: the desire for convenience. Taking a screenshot of a seed phrase feels safe. Storing it in your photo gallery feels like keeping it close. But in the world of cryptocurrency, that convenience comes with profound risk. Every image stored on a smartphone is a potential target for malware that operates silently in the background, exfiltrating data to servers controlled by criminals.

The discovery of SparkKitty inside official app stores proves that the threat is no longer theoretical and no longer confined to users who download apps from untrusted sources. It is inside the walls of the App Store and Google Play, inside the devices of tens of thousands of users, and operating with a level of sophistication that allowed it to remain undetected for over a year.

The message for cryptocurrency holders is clear: never store seed phrases digitally. Never assume that because an app is in an official store, it is safe. And always assume that every permission you grant is a door that could be opened against you. The photos on your phone may look harmless. To SparkKitty, they are the keys to your financial future.

Sources

Cet article est publié à titre informatif et éducatif. Il ne constitue en aucun cas un conseil en investissement. Faites vos propres recherches (DYOR) avant toute décision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles