• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

SparkKitty Malware Campaign Exposed by Check Point

user avatar

by Rajesh Kumar

36 minutes ago


A recent report from cybersecurity firm Check Point has unveiled alarming details about the SparkKitty malware campaign, which specifically targets cryptocurrency users. According to the results published in the material, this sophisticated malware scans photos on infected Android and iPhone devices for sensitive information, including wallet recovery phrases, posing a significant threat to digital asset security.

Introduction to SparkKitty Malware

First identified by Kaspersky in June 2025, the SparkKitty malware has been found to spread through various platforms, including the Apple App Store, Google Play, and third-party app stores. Its dual presence on both major app stores significantly broadens its attack surface, making it easier for unsuspecting users to download malicious applications disguised as legitimate tools.

Distribution and Functionality

The threat actor behind SparkKitty has cleverly distributed trojanized applications that masquerade as cryptocurrency tools, messaging platforms, and entertainment apps. Once users grant access to their photo libraries, the malware scans for wallet recovery phrases and other sensitive data, which is then uploaded to servers controlled by the attackers. Notably, on iOS, SparkKitty was hidden within a cryptocurrency app named Coin, which successfully evaded Apple's review process before requesting access to users' photos.

Android Presence and Variants

On the Android side, the malware was found in a messaging and cryptocurrency exchange app called SOEX, which garnered over 10,000 downloads from Google Play before its removal. Additionally, other variants of SparkKitty were distributed through:

  • third-party app stores
  • fake TikTok applications
  • gambling apps
  • sideloaded APKs

Targeting Techniques

Unlike typical information stealers that rely on clipboard monitoring or keylogging, SparkKitty directly targets users' photo libraries, making screenshots of wallet recovery phrases particularly vulnerable.

Mitigation Strategies

To mitigate the risks posed by SparkKitty, researchers advise users to:

  • keep wallet recovery phrases offline
  • limit photo library permissions to trusted applications
  • only download software from reputable developers

Users should remain vigilant against such threats.

In light of the recent SparkKitty malware threat targeting cryptocurrency users, it's crucial to consider Microsoft's earlier safety guidelines addressing the TrojanWin32CryptoBanditsA campaign. For more information, see safety tips.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

SparkKitty Malware Campaign Exposed by Check Point

chest

A report from Check Point reveals the SparkKitty malware campaign targeting cryptocurrency users by scanning photos on infected devices for sensitive information.

user avatarRajesh Kumar

Shiba Inu Token Experiences Remarkable 22% Surge

chest

Shiba Inu has experienced a significant price increase of nearly 22% in just one week, marking a notable change after a long period of stagnation.

user avatarFilippo Romano

Congress Proposes AI Kill Switch Legislation

chest

Congress members propose the AI Kill Switch Act to give the federal government authority to shut down AI models.

user avatarEmily Carter

Frax Governance Discusses Proposal for Early Redemptions from Locked Ethereum Pools

chest

Frax governance is discussing a proposal for early redemptions from locked Ethereum pools with a 4% penalty fee directed to the Frax treasury.

user avatarTomas Novak

Frax Governance Proposes Morpho Lending Market for bdUSD and frxUSD

chest

Frax governance is discussing a proposal to create a Morpho lending market for bdUSD and frxUSD to enhance stablecoin liquidity and borrowing demand.

user avatarKaterina Papadopoulou

EigenLayers Forum Engages in ELIP018 Proposal Discussion

chest

The EigenLayers forum is currently engaged in a debate over the draft proposal ELIP018, which introduces a framework known as RETIRE, aimed at providing a terminal exit route for restakers.

user avatarMaya Lundqvist

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.