
SparkKitty malware found in Apple App Store and Google Play scans photos for wallet seed phrases. The SOEX app was downloaded over 10,000 times before removal.
A new Check Point report details how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases. The malware spread through Apple's App Store, Google Play, and third-party app stores, the cybersecurity firm said.
Check Point first analyzed the campaign after Kaspersky disclosed it in June 2025. The firm wrote that the threat actor distributed trojanized applications disguised as legitimate cryptocurrency tools and messaging platforms. Some were even entertainment apps.
“What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface,” Check Point wrote.
After users granted access to their photo libraries, the malware scanned stored images for wallet recovery phrases and other sensitive information. The data was then uploaded to attacker-controlled servers.
On iOS, SparkKitty was distributed through a cryptocurrency app called "币coin" that was available on Apple's App Store. Check Point said the app concealed its malicious code to evade Apple's review process before requesting photo library access. On Android, the malware appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before being removed. Other variants spread through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs.
Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users' photo libraries directly. That made screenshots of wallet recovery phrases a prime target.
Researchers recommend keeping recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers.
The campaign follows a string of malware attacks on cryptocurrency users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet apps while stealing messages, passwords, photos, and other data from vulnerable iPhones. That same month, the FBI launched an investigation after several games distributed through Valve's Steam platform–including “Chemia,” “PirateFi,” and “Tokenova”–were found to install malware.
In May, AI startup Perplexity open-sourced Bumblebee, a security tool designed to detect compromised software packages, browser extensions, and AI connector configurations without executing potentially malicious code following a software supply-chain attack that affected more than 160 developer packages.
In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. The campaign deployed Lumma and Vidar infostealers, malware commonly used to steal browser credentials and cryptocurrency wallet data.
The SOEX app had been downloaded more than 10,000 times from Google Play before it was removed. Check Point did not say how many users were affected.
For broader context on crypto market analysis, the incident underscores the risks of storing seed phrases on internet-connected devices.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.