en

SparkKitty turns phone photos into a crypto wallet security risk

image
rubric logo Security
like fud 4

A mobile spyware campaign known as SparkKitty has returned to attention after reports warned that infected iOS and Android apps can expose crypto wallet recovery phrases stored in phone galleries.

The malware gains photo access, collects images and sends them to attacker-controlled servers.

However, this is not a newly discovered July 2026 threat. Kaspersky published a technical report on June 23, 2025, after finding SparkKitty in Apple’s App Store, Google Play and unofficial channels. A recent Cyberint article has renewed attention around the same malware family.

SparkKitty campaign dates back to 2024

Kaspersky linked SparkKitty to SparkCat, an earlier mobile stealer that used optical character recognition to search screenshots for wallet seed phrases. SparkKitty used related delivery methods, but many samples uploaded gallery images rather than selecting only files containing recovery words.

JUST IN: 🔒 Check Point has identified "SparkKitty" malware embedded in mobile apps that actively scans your photo library for cryptocurrency wallet seed phrases. If your seed is in a screenshot, it is already compromised. pic.twitter.com/hGoJWs0TEM

— BTC Live (@btcliveco) July 27, 2026

Researchers also found a related cluster that used OCR to choose particular images. The malware may therefore expose passwords, identity documents and QR codes. Kaspersky said it “believe[s]” the main goal involved crypto assets, while noting that some samples lacked direct proof.

The campaign had operated since at least February 2024 and mainly targeted Southeast Asia and China. As crypto.news reported in June 2025, it spread through fake crypto tools, modified social apps, gambling products and other applications.

In April 2026, Kaspersky reported a new SparkCat variant in two App Store apps and one Google Play app. That finding showed continued use of OCR-based gallery theft, but it did not confirm that SparkKitty itself had returned.

Malware uses photo permissions to steal data

On iOS, researchers found malicious code inside modified frameworks that imitated common development libraries, including AFNetworking and Alamofire. Other versions hid the payload in an obfuscated file named libswiftDarwin.dylib or placed it directly inside an application.

After launch, the malware contacted remote infrastructure and requested access to the photo gallery. Once a user approved the request, it monitored photos and uploaded files that it had not previously sent. It could also collect newly added images.

On Android, SparkKitty appeared in Java and Kotlin versions. Some samples operated as Xposed modules on rooted devices. They contacted command servers and transferred images with information about the infected device and application.

This approach differs from malware that records keystrokes or replaces copied wallet addresses. As crypto.news reported in June 2026, Microsoft tracked separate clipper malware that watched the clipboard, stole wallet credentials and supported backdoor commands.

Infected apps reached official stores

Kaspersky found an Android messaging app with crypto exchange functions on Google Play. The app, named SOEX, recorded more than 10,000 installations before Google removed it after receiving the researcher’s report.

The team also found an iOS crypto app called 币coin in Apple’s App Store. Kaspersky alerted Apple and updated its report on June 25, 2025, to say that Apple had removed the app. Researchers did not determine whether developers knowingly added the malware.

Other versions spread through fake websites, modified TikTok apps, gambling products and directly installed Android packages. Some iPhone campaigns abused enterprise provisioning tools, which let organisations distribute internal apps outside the public App Store.

The latest reporting does not establish that the named applications returned to official stores in July 2026. It also provides no confirmed victim count or total crypto losses. The original listings were removed, while sideloaded copies may still circulate.

Offline seed storage remains the main defence

A seed phrase usually contains 12 or 24 words that can restore every private key linked to a self-custody wallet. Anyone who obtains those words can recreate the wallet and transfer its assets. Changing an app password cannot secure an exposed recovery phrase.

Users should not keep seed phrases in screenshots, cloud albums, email drafts or notes apps. The crypto.news 2026 wallet guide recommends writing the phrase on paper or recording it on metal, then storing it offline securely.

Users should review photo permissions and remove access from apps that do not need it. They should avoid unofficial stores, modified apps and unknown download links. An official listing lowers some risks but does not remove the need to check the developer and requested permissions.

Anyone who believes SparkKitty exposed a seed phrase should create a new wallet on a clean device and move remaining assets immediately. The user should then remove the suspected app, update the device and rotate credentials stored in gallery images.

Current reports have renewed the warning around SparkKitty, but the public technical record traces the campaign to Kaspersky’s 2025 disclosure rather than a new July 2026 discovery.