Cybersecurity researchers have identified a malware campaign known as SparkKitty that targets cryptocurrency holders by scanning photos stored on infected smartphones for wallet recovery phrases. According to a new report from Check Point Research, the malware infected both iPhone and Android devices after being distributed through official app stores and third-party marketplaces.
Originally discovered by Kaspersky in June 2025, SparkKitty has now been analyzed in greater detail, revealing how it infiltrated Apple's App Store, Google Play, and unofficial app stores by disguising itself as legitimate applications.
The researchers added that the attackers disguised the malware as cryptocurrency tools, messaging applications, and entertainment apps, increasing the likelihood that unsuspecting users would install it.
Malware Searches Photos for Seed Phrases
Unlike traditional crypto-stealing malware that monitors keyboards or clipboards, SparkKitty focuses on users' photo libraries. Once installed, the application requests permission to access stored photos.
If access is granted, the malware scans images for cryptocurrency wallet recovery phrases (seed phrases) and other potentially sensitive information before uploading the data to attacker-controlled servers.
Because many users store screenshots of their wallet backup phrases on their phones, these images become valuable targets for attackers seeking complete control of crypto wallets.
The approach highlights an increasingly common security risk, where convenience can unintentionally expose users' most valuable digital assets.
Malicious Apps Reached Official App Stores
SparkKitty successfully bypassed security checks on both major mobile platforms. On iOS, the malware was distributed through a cryptocurrency application called "币coin", which appeared on Apple's App Store.
According to Check Point, the malicious code was carefully concealed to avoid detection during Apple's review process before requesting access to users' photo libraries.
On Android, SparkKitty appeared inside a cryptocurrency exchange and messaging application called SOEX, which accumulated more than 10,000 downloads on Google Play before being removed.
Researchers also discovered additional versions of the malware distributed through:
- Third-party Android app stores
- Fake TikTok applications
- Online gambling apps
- Sideloaded APK files
The broad distribution strategy significantly increased the malware's potential reach across cryptocurrency users.
Researchers Recommend Offline Wallet Backups
Security experts are urging cryptocurrency users to avoid storing recovery phrases as digital images. Instead, seed phrases should be written down and stored securely offline, where malware cannot access them.
Researchers also recommend granting photo library permissions only to trusted applications and downloading software exclusively from reputable developers.
The SparkKitty campaign follows several other high-profile attacks targeting cryptocurrency users. Earlier this year, Google disclosed the DarkSword exploit chain capable of stealing wallet data from vulnerable iPhones, while the FBI investigated malware distributed through several games on Steam.
More recently, Kaspersky reported attackers using Steam Workshop to spread Lumma and Vidar infostealers disguised as anime-themed wallpapers, further illustrating how cybercriminals continue to adapt their tactics to target cryptocurrency investors.
The latest findings serve as another reminder that protecting wallet recovery phrases remains one of the most critical aspects of cryptocurrency security, regardless of which device or platform users rely on.



