News
SparkKitty Malware Steals Seed Phrases by Scanning Photos in Mobile Apps
en
On July 27, according to The Block, security company Check Point disclosed that the cross-platform malware family SparkKitty was embedded in applications on the Apple App Store, Google Play, and third-party Android stores. It steals cryptocurrency wallet mnemonic phrases by scanning images in users' photo albums using optical character recognition (OCR). Attackers disguised SparkKitty as cryptocurrency services, chat tools, and entertainment apps. After requesting access to photo albums, they continuously scanned existing and newly added photos, uploading identified mnemonic phrases, passwords, QR code information, and device information to a remote server. Discovered samples include the "币 coin" app on iOS and the "SOEX" app on Android (which had over 10,000 downloads before being removed). Some variants spread through third-party stores, modified versions of TikTok, and gambling apps, and maintained persistence on rooted devices using Xposed modules. Security experts remind users to avoid taking screenshots or photos to save mnemonic phrases, store recovery phrases offline, and regularly review app album access permissions.