SparkKitty malware hidden in mobile apps scans photos for crypto wallet seed phrases

Quick Take

  • Check Point detailed SparkKitty, a cross-platform malware family that scans photos on Android and iOS devices for cryptocurrency wallet seed phrases using optical character recognition.
  • The malware was distributed through both official app stores and third-party channels, including an Android app that surpassed 10,000 downloads before its removal.
Advertisement

SparkKitty, a cross-platform malware family targeting cryptocurrency users, has been distributed through Apple's App Store, Google Play and third-party Android app stores, according to Check Point, which detailed the malware in a report published Sunday.

The malware searches images stored on infected devices for cryptocurrency wallet recovery phrases using optical character recognition (OCR), allowing attackers to extract sensitive credentials without relying on keystroke logging or clipboard monitoring.

Check Point said SparkKitty appears to be an evolution of SparkCat, an OCR-based stealer that Kaspersky documented in 2025 and that also pulled data from screenshots.

The security firm noted that SparkKitty spreads through trojanized applications masquerading as cryptocurrency services, messaging platforms and entertainment apps. Once installed, the applications request permission to access a user's photo library before continuously scanning existing and newly added images.

According to the report, text extracted from images, including wallet seed phrases, passwords and QR code data, is transmitted to attacker-controlled command-and-control infrastructure together with basic device information.

How SparkKitty works 

On iOS, Check Point said the malware was embedded in a cryptocurrency-related application called "币coin" that was available through the App Store. The report said the malicious functionality was concealed within obfuscated frameworks, including AFNetworking and libswiftDarwin.dylib, enabling the application to pass Apple's review process. 

It remains unclear whether the developer account behind the application was compromised or knowingly involved.

On Android, researchers identified SparkKitty inside an application called "SOEX," which presented itself as a messaging and cryptocurrency exchange platform. The application accumulated more than 10,000 downloads on Google Play before being removed, according to Check Point.

The report said additional Android variants were distributed through third-party app stores, sideloaded APKs, modified TikTok applications, and gambling apps. On rooted devices, some samples used Xposed framework modules to maintain persistence. 

Check Point said users who store wallet recovery phrases as screenshots or photographs face the greatest exposure, because possession of a seed phrase enables complete access to a compatible cryptocurrency wallet.

The report recommends avoiding screenshots of wallet recovery phrases, restricting photo library permissions to applications that require them, downloading software only from trusted sources, and reviewing application permissions regularly. 

It also advises storing recovery phrases offline, such as on paper or in hardware wallet backup solutions, rather than in a device's photo gallery.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.