“What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface,” Check Point wrote. “The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.”
After users granted access to their photo libraries, the malware scanned stored images for wallet recovery phrases and other sensitive information before uploading the data to attacker-controlled servers.
On iOS, SparkKitty was distributed through a cryptocurrency app called "币coin" that was available on Apple's App Store. Check Point said the app concealed its malicious code to evade Apple's review process before requesting access to users' photo libraries. On Android, the malware appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before being removed. Other variants were distributed through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs.
Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users' photo libraries directly, making screenshots of wallet recovery phrases a prime target.
Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers.



















