Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Claude AI Vulnerability Exposes Local Files to Malicious Repositories
July 27, 2026
Fake Windows App Sites Deliver Malware
July 27, 2026
Windows 11 File Explorer Speeds Up Large File Deletions
July 27, 2026
Home/Threats/SparkKitty Malware Steals Crypto Seed Phrases From iOS and Android Photos
Threats

SparkKitty Malware Steals Crypto Seed Phrases From iOS and Android Photos

Key Takeaways A new mobile malware, SparkKitty, is actively targeting cryptocurrency users on both iOS and Android devices. SparkKitty employs optical character recognition (OCR) to extract crypto...

David kimber
David kimber
July 27, 2026 5 Min Read
4 0

Key Takeaways

  • A new mobile malware, SparkKitty, is actively targeting cryptocurrency users on both iOS and Android devices.
  • SparkKitty employs optical character recognition (OCR) to extract crypto wallet seed phrases and other sensitive data from images and screenshots stored in users’ photo galleries.
  • The malware has successfully infiltrated official app marketplaces, including Google Play and the Apple App Store, disguised as legitimate cryptocurrency tools, messaging apps, and entertainment software.
  • Successful infection can lead to the complete compromise and draining of cryptocurrency wallets, as a single seed phrase grants full access to funds.

SparkKitty Malware Targets Mobile Crypto Users with OCR Photo Scanning

A sophisticated new mobile threat, dubbed SparkKitty, has emerged, specifically designed to pilfer cryptocurrency seed phrases from users’ mobile devices. This malware operates across both iOS and Android platforms, employing an innovative technique to bypass traditional security measures.

Table Of Content

  • Key Takeaways
  • SparkKitty Malware Targets Mobile Crypto Users with OCR Photo Scanning
  • How SparkKitty Operates and Spreads
  • Distribution Channels and Infection Vectors
  • What You Should Do

Unlike common stealers that log keystrokes or monitor clipboard activity, SparkKitty leverages optical character recognition (OCR) technology. It scans images and screenshots stored in a device’s photo gallery, identifying and extracting sensitive textual information, primarily cryptocurrency wallet recovery phrases.

The campaign has already achieved significant reach, successfully distributing malicious applications through official app marketplaces. This broad distribution vector puts a wide range of everyday users at risk, as they unknowingly download compromised software disguised as legitimate applications.

Upon installation, SparkKitty requests access to the device’s photo library. Once granted, it systematically scans images for specific sensitive strings, then transmits the collected data to remote command-and-control (C2) servers operated by the attackers. Researchers at Check Point were instrumental in identifying this threat and detailing its propagation methods, which primarily involve trojanized applications masquerading as popular crypto utilities, communication platforms, and entertainment software.

Check Point said in a report that SparkKitty represents a direct evolution of an earlier malware family known as SparkCat. The implications of this threat are severe; a single compromised seed phrase can grant attackers complete control over a cryptocurrency wallet, allowing them to drain funds within moments. Victims often remain unaware of the compromise until their digital assets vanish. The malware operates stealthily in the background after receiving initial gallery permissions, also collecting device metadata to refine future attack campaigns. Its widespread availability through both official and third-party app stores significantly expands its potential victim pool beyond niche crypto communities.

How SparkKitty Operates and Spreads

SparkKitty’s unique approach capitalizes on a common user habit: storing recovery phrases as screenshots or photos for convenience. The malware is specifically engineered to detect these images. After gaining photo access, it continuously monitors the image folders, applying its OCR capabilities to both new and existing files.

On iOS, the malicious payload was embedded within a cryptocurrency-themed application named “币coin” that appeared on the App Store. Advanced obfuscation techniques helped it evade initial security reviews. For Android users, an application called “SOEX,” posing as a messaging and exchange platform, garnered over 10,000 downloads on Google Play before its eventual removal. Variants of SparkKitty have also been observed spreading through unofficial third-party app stores, modified TikTok clones, and gambling applications, reflecting a common distribution pattern for malicious Android software.

Extracted data, including seed phrases, passwords, and QR code information, is covertly transmitted to the attackers’ command-and-control infrastructure, alongside basic device metadata. Users who store sensitive recovery information as plain screenshots are at the highest risk. This method can also capture other secrets stored in image format, turning a seemingly innocuous photo backup into a critical security vulnerability for digital asset holders.

Distribution Channels and Infection Vectors

SparkKitty’s distribution leverages two primary channels: official app store listings and sideloaded packages. Official store presence lends credibility and facilitates rapid, large-scale infections, while sideloaded APKs and modules for rooted Android devices (utilizing frameworks like Xposed) offer enhanced persistence. Both methods typically involve requesting gallery access shortly after installation, enabling the scanning process to commence without further user interaction.

Security teams monitoring the removal of malicious apps from Google Play note that even a brief period of availability can lead to thousands of infections. Once active, SparkKitty persistently monitors for new images, meaning any subsequent screenshots of wallet information also become vulnerable. Individuals managing online crypto payments should view any unexpected request for photo library access as a critical warning sign.

What You Should Do

  • Avoid Unknown Sources: Only install cryptocurrency, messaging, or financial applications from reputable, official sources. Exercise extreme caution with third-party app stores or direct downloads.
  • Review App Permissions: Scrutinize all permission requests upon installing new applications. Deny gallery or media access unless it is absolutely essential for the app’s core functionality.
  • Never Store Seed Phrases as Images: Do not take screenshots or photos of your cryptocurrency wallet seed phrases, private keys, or other sensitive recovery information. This is a critical security risk.
  • Utilize Secure Storage: Opt for hardware wallets (cold storage) or secure, offline paper backups stored in physically protected locations for your seed phrases.
  • Keep Devices Updated: Ensure your operating system and all applications are regularly updated to benefit from the latest security patches.
  • Regularly Audit Permissions: Periodically review the permissions granted to all installed applications and revoke access that is no longer necessary or seems suspicious.
  • Suspected Infection Protocol: If you suspect your device is compromised, immediately disconnect it from all networks (Wi-Fi and cellular). Use a clean, separate device to transfer any remaining cryptocurrency funds to a new, secure wallet. Promptly rotate all related credentials and passwords.

Indicators of Compromise (IoCs):-

Type Indicator Description
MD5 7e678ca2f01dc853e85d13924e6c8a45 SparkKitty sample hash
MD5 8d45a67b648d2cb46292ff5041a5dd44 SparkKitty sample hash
MD5 79fe383f0963ae741193989c12aefacc SparkKitty sample hash
MD5 bafba3d044a4f674fc9edc67ef6b8a6b SparkKitty sample hash
MD5 d48b580718b0e1617afc1dec028e9059 SparkKitty sample hash
MD5 b639f7f81a8faca9c62fd227fef5e28c SparkKitty sample hash
MD5 4126348d783393dd85ede3468e48405d SparkKitty sample hash
MD5 fe0868c4f40cbb42eb58af121570e64d SparkKitty sample hash
MD5 fd4558a9b629b5abe65a649b57bef20c SparkKitty sample hash
MD5 fa0e99bac48bc60aa0ae82bc0fd1698d SparkKitty sample hash
MD5 f9ab4769b63a571107f2709b5b14e2bc SparkKitty sample hash
MD5 f10a4fdffc884089ae93b0372ff9d5d1 SparkKitty sample hash
MD5 f0815908bafd88d71db660723b65fba4 SparkKitty sample hash
MD5 f0460bdca0f04d3bd4fc59d73b52233b SparkKitty sample hash
MD5 ec068e0fc6ffda97685237d8ab8a0f56 SparkKitty sample hash
MD5 e9f7d9bc988e7569f999f0028b359720 SparkKitty sample hash
MD5 e8b60bf5af2d5cc5c501b87d04b8a6c2 SparkKitty sample hash
MD5 e5186be781f870377b6542b3cecfb622 SparkKitty sample hash
MD5 d851b19b5b587f202795e10b72ced6e1 SparkKitty sample hash
MD5 d4f42319a78b6605cabb5696bacb4677 SparkKitty sample hash
MD5 ce49a90c0a098e8737e266471d323626 SparkKitty sample hash
MD5 cc919d4bbd3fb2098d1aeb516f356cca SparkKitty sample hash
MD5 c6a7568134622007de026d22257502d5 SparkKitty sample hash
MD5 c5be3ae482d25c6537e08c888a742832 SparkKitty sample hash
MD5 b4489cb4fac743246f29abf7f605dd15 SparkKitty sample hash
MD5 b3085cd623b57fd6561e964d6fd73413 SparkKitty sample hash
MD5 b0eda03d7e4265fe280360397c042494 SparkKitty sample hash
MD5 b0976d46970314532bc118f522bb8a6f SparkKitty sample hash
MD5 aa5ce6fed4f9d888cbf8d6d8d0cda07f SparkKitty sample hash
SHA-1 f9182892299b52b2236fd98c1262e2f0837e1683 SparkKitty sample hash
SHA-1 8a84ce9cbf239fc8a3e7e3ed0b4f0050b7113e92 SparkKitty sample hash
SHA-1 5861f7d50d9000fd43ea1552164e7d1f850f0c9b SparkKitty sample hash
SHA-256 cdbe32fcb10606846035fff7c2f54d1b4306ef08c SparkKitty sample hash
SHA-256 9ca063d5716155d9e70ebda9370655c65dcf82b SparkKitty sample hash
SHA-256 5b4d879862d8bd8af65a4151967990ef830b8c4 SparkKitty sample hash
URL yjhjymfjnj.wyxbmh.cn Command-and-control URL
URL xt.xinqianf38.top Command-and-control URL
URL lt.laoqianf51.top Command-and-control URL
URL lt.laoqianf15.top Command-and-control URL
URL lt.laoqianf14.top Command-and-control URL
URL i.bicoin.com.cn Command-and-control URL
URL h1997.tiktokapp.club Command-and-control URL
URL api.fxsdk.com Command-and-control URL
Domain moabc.vip Malicious domain
Domain byteepic.vip Malicious domain
Domain accgngrid.com Malicious domain
IPv4 47.119.171.161 Command-and-control IP
IPv4 39.108.186.119 Command-and-control IP
IPv4 23.249.28.88 Command-and-control IP
IPv4 120.79.8.107 Command-and-control IP

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks

Next Post

Windows 11 File Explorer Speeds Up Large File Deletions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
PyPI Blocks New File Uploads on Old Releases to Prevent Package Poisoning
July 27, 2026
BlueNoroff Hijacks Telegram Accounts to Deliver ClickFix Malware
July 27, 2026
Researchers Boot Jailbroken iOS 17 on iPhone 11 Pro
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us