Memes

New ‘SparkKitty’ Malware Targets Cryptocurrency Users

Kaspersky has issued a warning after discovering that a new malware called SparkKitty has been stealing crypto wallet seed phrases from Android and iOS devices.
SparkKitty Malware

Key Takeaways

  • SparkKitty is a new malware targeting Android and iOS devices by stealing all photos in the gallery to extract crypto wallet seed phrases.
  • It has been distributed through crypto-related apps like SOEX and 币coin, as well as gambling games and TikTok clones.
  • The malware originates from the same source as SparkCat, another crypto-targeting threat.
  • Although mainly affecting users in Southeast Asia and China, there are no regional limitations for potential infections.

How ‘SparkKitty’ Malware Works

In a detailed report released by Kaspersky analysts Sergey Puzan and Dmitry Kalinin, SparkKitty has been found targeting both Android and iOS users via apps available on Google Play and the Apple App Store.

The goal is to gain access to sensitive financial data by harvesting images from a user’s photo gallery.

 

SparkKitty Malware Victim

A SparkKitty Malware Victim

Source: Kaspersky

 

Once SparkKitty infiltrates a device, it silently begins copying all images stored in the device’s photo gallery. While its main objective appears to be locating screenshots of cryptocurrency wallet seed phrases, analysts warn that other forms of sensitive data may also be compromised.

This method of attack is especially dangerous as many users store wallet seed phrases, passwords, and even identification documents as screenshots, assuming their photo galleries are secure.

 

Malware Delivered Via Crypto-Themed Apps

Kaspersky identified at least two malicious apps used to distribute SparkKitty. These include:

  • 币coin: Posed as a crypto information tracker on the Apple App Store.
  • SOEX: Marketed as a messaging app with crypto exchange features, available on Google Play before being removed.

The SOEX app, in particular, had a substantial reach with over 10,000 installs before its removal. Upon Kaspersky’s report, Google confirmed that the app has been taken down and the developer banned.

 

SOEX Malware

SOEX Was Infected With The SparkKitty Malware

Source: Kaspersky

 

Kaspersky researchers have also found SparkKitty embedded in other seemingly unrelated apps, including adult games, gambling apps, and fake or malicious versions of TikTok.

 

Connection To SparkCat Malware

SparkKitty bears a strong resemblance to another malware strain named ‘SparkCat‘, which was discovered by Kaspersky earlier this year. Like SparkKitty, SparkCat scans through user photos in search of crypto wallet recovery phrases.

Both malware strains are believed to have originated from the same source due to overlapping features and similar file paths observed in the attackers’ infrastructure.

The researchers noted:

“While not technically or conceptually complex, this campaign has been ongoing since at least the beginning of 2024 and poses a significant threat to users.”

Unlike SparkCat, which selectively scanned images, SparkKitty indiscriminately harvests all photos, increasing the chances of capturing sensitive content.

 

Who Is Being Targeted?

While the campaign is global in scope, the primary focus appears to be on users in Southeast Asia and China. Many of the infected apps include Chinese-language content, gambling-related themes, and social media clones aimed at local demographics.

However, Kaspersky warns that there are no technical barriers preventing SparkKitty from targeting users elsewhere.

 

FAQ

How do I know if my phone is infected with SparkKitty?
SparkKitty works silently in the background and may not show obvious signs. If you’ve recently installed any unknown or crypto-themed apps not verified by major publishers, uninstall them and run a mobile security scan immediately.

What can SparkKitty do with my photos?
The malware aims to identify crypto wallet seed phrases in screenshots. However, it can also compromise other personal images that contain financial, legal, or identification information.

Are iOS users at risk too?
Yes. Although Android is more commonly targeted, one of the infected apps, 币coin, was found on the Apple App Store, proving that iOS users are not immune.

How can I protect myself?
Avoid downloading unknown apps, even from official app stores, use antivirus or mobile security tools from reputable providers, never store sensitive information like seed phrases in your gallery, and enable automatic updates and Google Play Protect.

CryptoHackMeme CoinScamSparkKitty

Join Our FREE Newsletter

Subscribe to stay informed and receive latest updates on the latest happenings in the crypto world!


By submitting this form, you are consenting to receive marketing emails from: Crypto Weekly. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Haider Jamal

Content Strategist

Haider is a fintech enthusiast and Content Strategist at CryptoWeekly with over four years in the Crypto & Blockchain industry. He began his writing journey with a blog after graduating from Monash University Malaysia. Passionate about storytelling and content creation, he blends creativity with insight. Haider is driven to grow professionally while always seeking the next big idea.

Read More >

Join Our FREE Newsletter

Subscribe to stay informed and receive latest updates on the latest happenings in the crypto world!


By submitting this form, you are consenting to receive marketing emails from: Crypto Weekly. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Search

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

News: