SparkKitty Malware in App Stores Targeted Crypto Wallet Seed Phrases
Key Takeaways
- •SparkKitty searched users’ photo libraries for cryptocurrency wallet recovery phrases after receiving photo access permissions.
- •Check Point said the malware appeared in apps distributed through Apple’s App Store, Google Play, third-party app stores, and sideloaded APK files.
- •The iOS version was linked to a cryptocurrency app called “币coin,” while the Android version appeared in SOEX before Google Play removed it.
- •Researchers advised users to keep wallet recovery phrases offline, limit photo permissions, and install software only from reputable developers.

Cybersecurity researchers say the SparkKitty malware campaign targeted cryptocurrency users by scanning photo libraries on infected Android and iPhone devices for wallet recovery phrases and other sensitive information.
According to a new report from cybersecurity firm Check Point, SparkKitty was distributed through malicious applications available on Apple's App Store, Google Play, and third-party app stores. The campaign highlights the risks of storing crypto wallet recovery phrases as screenshots, which can expose digital assets if an infected app receives access to a user's photos.
Recovery phrases, also known as seed phrases, are used to restore access to cryptocurrency wallets. Because control of those words can be enough to recover a wallet elsewhere, they are a high-value target for malware operators and phishing campaigns.
SparkKitty was first discovered by Kaspersky in June 2025. Check Point's analysis described how the malware reached users through app stores by appearing inside trojanized applications presented as legitimate cryptocurrency tools, messaging platforms, and entertainment apps.
“What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface,” Check Point wrote. “The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.”
Once users granted access to their photo libraries, SparkKitty searched stored images for wallet recovery phrases and other sensitive data. The malware then uploaded the collected information to servers controlled by the attackers.
On iOS, SparkKitty was distributed through a cryptocurrency app called "币coin" that was available on Apple's App Store. Check Point said the app hid its malicious code in order to evade Apple's review process, and then requested access to users' photo libraries after installation.
On Android, the malware appeared in SOEX, a messaging and cryptocurrency exchange app that was downloaded more than 10,000 times from Google Play before it was removed. Check Point also said other SparkKitty variants were spread through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APK files.
The campaign shows that official app-store availability does not remove the need to review app permissions, particularly when an application asks for broad access to photos or other local data unrelated to its core function.
SparkKitty differs from many information stealers that typically depend on clipboard monitoring or keylogging. Instead, it directly searched users' photo libraries, making screenshots of wallet recovery phrases a particularly valuable target for attackers.
Researchers recommend that users keep wallet recovery phrases offline rather than storing them as screenshots, restrict photo library permissions to trusted applications, and download software only from reputable developers.
The report comes amid a series of malware campaigns aimed at cryptocurrency users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet apps while stealing messages, passwords, photos, and other data from vulnerable iPhones.
Also in March, the FBI opened an investigation after several games distributed through Valve's Steam platform—including “Chemia,” “PirateFi,” and “Tokenova”—were found to install malware.
In May, AI startup Perplexity open-sourced Bumblebee, a security tool designed to detect compromised software packages, browser extensions, and AI connector configurations without executing potentially malicious code. The release followed a software supply-chain attack that affected more than 160 developer packages.
In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. That campaign deployed Lumma and Vidar infostealers, malware commonly used to steal browser credentials and cryptocurrency wallet data.