VYPR
malwarePublished Jul 27, 2026· 1 source

SparkKitty Malware Steals Crypto Seed Phrases from Mobile Photos Using OCR

A new malware strain, SparkKitty, targets iOS and Android users by scanning photo galleries for cryptocurrency wallet seed phrases using optical character recognition.

A novel mobile malware, dubbed SparkKitty, has emerged, posing a significant threat to cryptocurrency users by stealthily extracting sensitive wallet seed phrases directly from their photo galleries on both iOS and Android devices. Unlike traditional malware that relies on keylogging or clipboard monitoring, SparkKitty employs optical character recognition (OCR) technology to scan images, including screenshots, for recovery phrases. This sophisticated approach allows attackers to bypass conventional security measures by targeting data stored visually.

The malware's distribution strategy is particularly concerning, as it has been found embedded within trojanized applications available on official app stores, such as Google Play, as well as through third-party marketplaces. This widespread availability significantly increases the potential victim pool, encompassing everyday users who may not suspect malicious intent from seemingly legitimate applications. Once installed, SparkKitty requests and gains access to the device's photo library, systematically scanning all images for patterns indicative of seed phrases or other sensitive text.

Researchers from Check Point identified SparkKitty as a direct evolution of a previous malware family known as SparkCat, highlighting a growing trend of OCR-based data theft targeting mobile users. The impact of a successful compromise is severe, as a single leaked seed phrase can grant attackers complete control over a cryptocurrency wallet, enabling them to drain all funds rapidly. Victims often only realize their assets are gone when it's too late, with no immediate indication of the breach.

SparkKitty operates discreetly in the background after obtaining gallery permissions, minimizing the chances of detection. In addition to harvesting seed phrases, it also collects device metadata, which can be used by attackers to refine their campaigns and target future victims more effectively. The malware's presence on official app stores, such as an iOS app named "币coin" and an Android app called "SOEX" (which garnered over 10,000 downloads before removal), underscores the challenges in vetting applications for malicious behavior.

Variants of SparkKitty have also been observed spreading through less conventional channels, including third-party app stores, modified versions of popular applications like TikTok, and gambling applications. This multi-pronged distribution approach mirrors tactics previously seen with other malicious apps found on official marketplaces, indicating a persistent and evolving threat landscape. The extracted data, including seed phrases, passwords, and QR code information, is transmitted to the attackers' command-and-control infrastructure.

Users who store their cryptocurrency recovery phrases as images or screenshots are particularly vulnerable. The malware's ability to turn a common convenience into a critical security risk emphasizes the need for stringent security practices. Practical advice for users includes avoiding the installation of applications from untrusted sources, carefully reviewing app permissions, and never storing sensitive recovery information in easily accessible formats like photos.

To mitigate the risks associated with SparkKitty and similar threats, security experts recommend a multi-layered approach. This includes regularly reviewing app permissions, uninstalling any suspicious applications, and maintaining up-to-date device software. For cryptocurrency users, the best practice remains the use of hardware wallets or secure, offline paper backups stored in physically safe locations. Promptly rotating credentials and moving funds to a clean device are crucial steps if an infection is suspected.

The Indicators of Compromise (IoCs) provided include numerous MD5 hashes associated with SparkKitty samples, serving as critical identifiers for security software and analysts to detect and block the malware. These hashes represent specific versions or variants of the malicious software, aiding in the ongoing effort to track and neutralize the threat.

Synthesized by Vypr AI