SparkKitty Malware Steals Crypto Seed Phrases From iOS and Android Photos
Key Takeaways A new mobile malware, SparkKitty, is actively targeting cryptocurrency users on both iOS and Android devices. SparkKitty employs optical character recognition (OCR) to extract crypto...
Key Takeaways
- A new mobile malware, SparkKitty, is actively targeting cryptocurrency users on both iOS and Android devices.
- SparkKitty employs optical character recognition (OCR) to extract crypto wallet seed phrases and other sensitive data from images and screenshots stored in users’ photo galleries.
- The malware has successfully infiltrated official app marketplaces, including Google Play and the Apple App Store, disguised as legitimate cryptocurrency tools, messaging apps, and entertainment software.
- Successful infection can lead to the complete compromise and draining of cryptocurrency wallets, as a single seed phrase grants full access to funds.
SparkKitty Malware Targets Mobile Crypto Users with OCR Photo Scanning
A sophisticated new mobile threat, dubbed SparkKitty, has emerged, specifically designed to pilfer cryptocurrency seed phrases from users’ mobile devices. This malware operates across both iOS and Android platforms, employing an innovative technique to bypass traditional security measures.
Table Of Content
Unlike common stealers that log keystrokes or monitor clipboard activity, SparkKitty leverages optical character recognition (OCR) technology. It scans images and screenshots stored in a device’s photo gallery, identifying and extracting sensitive textual information, primarily cryptocurrency wallet recovery phrases.
The campaign has already achieved significant reach, successfully distributing malicious applications through official app marketplaces. This broad distribution vector puts a wide range of everyday users at risk, as they unknowingly download compromised software disguised as legitimate applications.
Upon installation, SparkKitty requests access to the device’s photo library. Once granted, it systematically scans images for specific sensitive strings, then transmits the collected data to remote command-and-control (C2) servers operated by the attackers. Researchers at Check Point were instrumental in identifying this threat and detailing its propagation methods, which primarily involve trojanized applications masquerading as popular crypto utilities, communication platforms, and entertainment software.
Check Point said in a report that SparkKitty represents a direct evolution of an earlier malware family known as SparkCat. The implications of this threat are severe; a single compromised seed phrase can grant attackers complete control over a cryptocurrency wallet, allowing them to drain funds within moments. Victims often remain unaware of the compromise until their digital assets vanish. The malware operates stealthily in the background after receiving initial gallery permissions, also collecting device metadata to refine future attack campaigns. Its widespread availability through both official and third-party app stores significantly expands its potential victim pool beyond niche crypto communities.
How SparkKitty Operates and Spreads
SparkKitty’s unique approach capitalizes on a common user habit: storing recovery phrases as screenshots or photos for convenience. The malware is specifically engineered to detect these images. After gaining photo access, it continuously monitors the image folders, applying its OCR capabilities to both new and existing files.
On iOS, the malicious payload was embedded within a cryptocurrency-themed application named “币coin” that appeared on the App Store. Advanced obfuscation techniques helped it evade initial security reviews. For Android users, an application called “SOEX,” posing as a messaging and exchange platform, garnered over 10,000 downloads on Google Play before its eventual removal. Variants of SparkKitty have also been observed spreading through unofficial third-party app stores, modified TikTok clones, and gambling applications, reflecting a common distribution pattern for malicious Android software.
Extracted data, including seed phrases, passwords, and QR code information, is covertly transmitted to the attackers’ command-and-control infrastructure, alongside basic device metadata. Users who store sensitive recovery information as plain screenshots are at the highest risk. This method can also capture other secrets stored in image format, turning a seemingly innocuous photo backup into a critical security vulnerability for digital asset holders.
Distribution Channels and Infection Vectors
SparkKitty’s distribution leverages two primary channels: official app store listings and sideloaded packages. Official store presence lends credibility and facilitates rapid, large-scale infections, while sideloaded APKs and modules for rooted Android devices (utilizing frameworks like Xposed) offer enhanced persistence. Both methods typically involve requesting gallery access shortly after installation, enabling the scanning process to commence without further user interaction.
Security teams monitoring the removal of malicious apps from Google Play note that even a brief period of availability can lead to thousands of infections. Once active, SparkKitty persistently monitors for new images, meaning any subsequent screenshots of wallet information also become vulnerable. Individuals managing online crypto payments should view any unexpected request for photo library access as a critical warning sign.
What You Should Do
- Avoid Unknown Sources: Only install cryptocurrency, messaging, or financial applications from reputable, official sources. Exercise extreme caution with third-party app stores or direct downloads.
- Review App Permissions: Scrutinize all permission requests upon installing new applications. Deny gallery or media access unless it is absolutely essential for the app’s core functionality.
- Never Store Seed Phrases as Images: Do not take screenshots or photos of your cryptocurrency wallet seed phrases, private keys, or other sensitive recovery information. This is a critical security risk.
- Utilize Secure Storage: Opt for hardware wallets (cold storage) or secure, offline paper backups stored in physically protected locations for your seed phrases.
- Keep Devices Updated: Ensure your operating system and all applications are regularly updated to benefit from the latest security patches.
- Regularly Audit Permissions: Periodically review the permissions granted to all installed applications and revoke access that is no longer necessary or seems suspicious.
- Suspected Infection Protocol: If you suspect your device is compromised, immediately disconnect it from all networks (Wi-Fi and cellular). Use a clean, separate device to transfer any remaining cryptocurrency funds to a new, secure wallet. Promptly rotate all related credentials and passwords.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| MD5 | 7e678ca2f01dc853e85d13924e6c8a45 | SparkKitty sample hash |
| MD5 | 8d45a67b648d2cb46292ff5041a5dd44 | SparkKitty sample hash |
| MD5 | 79fe383f0963ae741193989c12aefacc | SparkKitty sample hash |
| MD5 | bafba3d044a4f674fc9edc67ef6b8a6b | SparkKitty sample hash |
| MD5 | d48b580718b0e1617afc1dec028e9059 | SparkKitty sample hash |
| MD5 | b639f7f81a8faca9c62fd227fef5e28c | SparkKitty sample hash |
| MD5 | 4126348d783393dd85ede3468e48405d | SparkKitty sample hash |
| MD5 | fe0868c4f40cbb42eb58af121570e64d | SparkKitty sample hash |
| MD5 | fd4558a9b629b5abe65a649b57bef20c | SparkKitty sample hash |
| MD5 | fa0e99bac48bc60aa0ae82bc0fd1698d | SparkKitty sample hash |
| MD5 | f9ab4769b63a571107f2709b5b14e2bc | SparkKitty sample hash |
| MD5 | f10a4fdffc884089ae93b0372ff9d5d1 | SparkKitty sample hash |
| MD5 | f0815908bafd88d71db660723b65fba4 | SparkKitty sample hash |
| MD5 | f0460bdca0f04d3bd4fc59d73b52233b | SparkKitty sample hash |
| MD5 | ec068e0fc6ffda97685237d8ab8a0f56 | SparkKitty sample hash |
| MD5 | e9f7d9bc988e7569f999f0028b359720 | SparkKitty sample hash |
| MD5 | e8b60bf5af2d5cc5c501b87d04b8a6c2 | SparkKitty sample hash |
| MD5 | e5186be781f870377b6542b3cecfb622 | SparkKitty sample hash |
| MD5 | d851b19b5b587f202795e10b72ced6e1 | SparkKitty sample hash |
| MD5 | d4f42319a78b6605cabb5696bacb4677 | SparkKitty sample hash |
| MD5 | ce49a90c0a098e8737e266471d323626 | SparkKitty sample hash |
| MD5 | cc919d4bbd3fb2098d1aeb516f356cca | SparkKitty sample hash |
| MD5 | c6a7568134622007de026d22257502d5 | SparkKitty sample hash |
| MD5 | c5be3ae482d25c6537e08c888a742832 | SparkKitty sample hash |
| MD5 | b4489cb4fac743246f29abf7f605dd15 | SparkKitty sample hash |
| MD5 | b3085cd623b57fd6561e964d6fd73413 | SparkKitty sample hash |
| MD5 | b0eda03d7e4265fe280360397c042494 | SparkKitty sample hash |
| MD5 | b0976d46970314532bc118f522bb8a6f | SparkKitty sample hash |
| MD5 | aa5ce6fed4f9d888cbf8d6d8d0cda07f | SparkKitty sample hash |
| SHA-1 | f9182892299b52b2236fd98c1262e2f0837e1683 | SparkKitty sample hash |
| SHA-1 | 8a84ce9cbf239fc8a3e7e3ed0b4f0050b7113e92 | SparkKitty sample hash |
| SHA-1 | 5861f7d50d9000fd43ea1552164e7d1f850f0c9b | SparkKitty sample hash |
| SHA-256 | cdbe32fcb10606846035fff7c2f54d1b4306ef08c | SparkKitty sample hash |
| SHA-256 | 9ca063d5716155d9e70ebda9370655c65dcf82b | SparkKitty sample hash |
| SHA-256 | 5b4d879862d8bd8af65a4151967990ef830b8c4 | SparkKitty sample hash |
| URL | yjhjymfjnj.wyxbmh.cn | Command-and-control URL |
| URL | xt.xinqianf38.top | Command-and-control URL |
| URL | lt.laoqianf51.top | Command-and-control URL |
| URL | lt.laoqianf15.top | Command-and-control URL |
| URL | lt.laoqianf14.top | Command-and-control URL |
| URL | i.bicoin.com.cn | Command-and-control URL |
| URL | h1997.tiktokapp.club | Command-and-control URL |
| URL | api.fxsdk.com | Command-and-control URL |
| Domain | moabc.vip | Malicious domain |
| Domain | byteepic.vip | Malicious domain |
| Domain | accgngrid.com | Malicious domain |
| IPv4 | 47.119.171.161 | Command-and-control IP |
| IPv4 | 39.108.186.119 | Command-and-control IP |
| IPv4 | 23.249.28.88 | Command-and-control IP |
| IPv4 | 120.79.8.107 | Command-and-control IP |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.