A recent report from cybersecurity firm Check Point has unveiled alarming details about the SparkKitty malware campaign, which specifically targets cryptocurrency users. According to the results published in the material, this sophisticated malware scans photos on infected Android and iPhone devices for sensitive information, including wallet recovery phrases, posing a significant threat to digital asset security.
Introduction to SparkKitty Malware
First identified by Kaspersky in June 2025, the SparkKitty malware has been found to spread through various platforms, including the Apple App Store, Google Play, and third-party app stores. Its dual presence on both major app stores significantly broadens its attack surface, making it easier for unsuspecting users to download malicious applications disguised as legitimate tools.
Distribution and Functionality
The threat actor behind SparkKitty has cleverly distributed trojanized applications that masquerade as cryptocurrency tools, messaging platforms, and entertainment apps. Once users grant access to their photo libraries, the malware scans for wallet recovery phrases and other sensitive data, which is then uploaded to servers controlled by the attackers. Notably, on iOS, SparkKitty was hidden within a cryptocurrency app named Coin, which successfully evaded Apple's review process before requesting access to users' photos.
Android Presence and Variants
On the Android side, the malware was found in a messaging and cryptocurrency exchange app called SOEX, which garnered over 10,000 downloads from Google Play before its removal. Additionally, other variants of SparkKitty were distributed through:
- third-party app stores
- fake TikTok applications
- gambling apps
- sideloaded APKs
Targeting Techniques
Unlike typical information stealers that rely on clipboard monitoring or keylogging, SparkKitty directly targets users' photo libraries, making screenshots of wallet recovery phrases particularly vulnerable.
Mitigation Strategies
To mitigate the risks posed by SparkKitty, researchers advise users to:
- keep wallet recovery phrases offline
- limit photo library permissions to trusted applications
- only download software from reputable developers
Users should remain vigilant against such threats.
In light of the recent SparkKitty malware threat targeting cryptocurrency users, it's crucial to consider Microsoft's earlier safety guidelines addressing the TrojanWin32CryptoBanditsA campaign. For more information, see safety tips.







