
Kaspersky uncovered SparkKitty malware inside Apple and Google app stores that uses OCR to steal crypto wallet seed phrases from phone photos. Active since Feb 2024.
Kaspersky researchers on June 23 published findings on SparkKitty, a mobile spyware Trojan that made its way into both the Apple App Store and Google Play. The malware rummages through users' photo galleries, uses optical character recognition to spot screenshots of crypto wallet seed phrases, and uploads those images to attacker-controlled servers.
Kaspersky said the malware has been active since at least February 2024, operating unnoticed for more than a year. It is linked to the SparkCat campaign the firm first reported in January 2025, suggesting an ongoing and evolving effort rather than a one-off attack.
On iOS, the malware was hidden inside an app called 币coin, a crypto-rate tracking application. On Google Play, it rode inside SOEX, a messaging app that included crypto-exchange functionality and had accumulated over 10,000 installs before being pulled. The Trojan also spread through unauthorized distribution channels, including modified versions of TikTok, and primarily targeted users in China and Southeast Asia, according to Kaspersky.
Both Apple and Google removed the infected applications after Kaspersky disclosed its findings.
The malware used OCR, the same technology that lets phones scan documents, to read text within images. It specifically searched for patterns matching seed phrase formats. Once it found a match, the image was exfiltrated to servers controlled by the attackers, who could then reconstruct the wallet and drain its contents.
On iOS, the malware disguised itself with fake frameworks designed to mimic legitimate networking libraries like AFNetworking and Alamofire. On Android, it leveraged malicious enterprise provisioning profiles to sideload itself onto devices.
A seed phrase is the master key to a crypto wallet. Anyone who possesses it can access every asset stored within. Unlike a compromised password, there is no reset option. Once someone has your seed phrase, your funds are gone, and blockchain transactions are irreversible.
The crypto market itself has not reacted to the news. Kaspersky's findings suggest the campaign was relatively targeted rather than broadly deployed. There has been no visible price impact or increased on-chain activity indicating mass wallet compromises.
For investors, the practical takeaway is operational security hygiene. Delete any screenshots of seed phrases immediately. Use a hardware wallet for significant holdings. Be skeptical of app permissions, particularly requests for photo gallery access from apps that have no business viewing your photos. A crypto price tracker has no legitimate reason to scan your camera roll.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.