SparkKitty Malware Found on Apple App Store, Google Play Targets Crypto Users
Summary
- A new malware strain, SparkKitty, was distributed through the App Store and Google Play, stealing cryptocurrency wallet recovery phrases.
- SparkKitty is an information-stealing malware strain that uses OCR technology to extract wallet recovery phrases, passwords and QR code data from images and send them to hacker-controlled servers.
- Check Point said a recovery phrase alone is enough to provide full access to a wallet and warned that crypto users who store it as a screenshot or photo face the greatest risk.
Forecast Trend Report by Period



A new malware strain targeting cryptocurrency users, known as SparkKitty, has been found on Apple’s App Store and Google Play.
Crypto-focused media outlet The Block reported on July 27 that cybersecurity firm Check Point said in a report released the same day that SparkKitty had been distributed through multiple channels, including the App Store, Google Play and third-party Android app markets. The malware uses optical character recognition, or OCR, to scan images stored on infected devices and extract cryptocurrency wallet recovery phrases, also known as seed phrases.
Check Point said SparkKitty appears to be an evolved version of SparkCat, an information-stealing malware strain reported previously. SparkCat also used OCR to collect data from screenshots.
The malware was distributed inside applications disguised as crypto services, messaging platforms and entertainment apps. After installation, it requests access to a user’s photo library. It then continuously scans both existing and newly added images stored on the device. Extracted wallet recovery phrases, passwords and QR code data are sent to servers controlled by hackers, along with basic device information.
On iOS, the malware was embedded in a crypto-related app listed on the App Store under the name Bcoin. On Android, SparkKitty was found in an app called SOEX that was disguised as a messaging and crypto trading platform. It was downloaded more than 10,000 times before being removed from Google Play.
Check Point said a recovery phrase alone is enough to give someone full access to a wallet. Crypto users who store wallet recovery phrases as screenshots or photos face the greatest risk.
Uk Jin
wook9629@bloomingbit.ioH3LLO, World! I am Uk Jin.