SparkKitty Malware Targets Crypto Wallets via App Stores
A new malware campaign called SparkKitty has infiltrated Apple's App Store and Google Play, scanning photo libraries for crypto wallet seed phrases. Check Point reports that trojanized apps like 币coin and SOEX exfiltrated sensitive data, highlighting the danger of storing recovery phrases as screenshots.
Quick Take
SparkKitty malware spread via Apple App Store, Google Play, and third-party stores.
iOS app "币coin" and Android app SOEX (10,000+ downloads) were trojanized.
Malware scans photo libraries directly for seed phrase screenshots.
Researchers urge offline storage and limiting photo permissions.
Market Impact Analysis
BearishMalware targeting crypto users via official app stores erodes trust and highlights security vulnerabilities, potentially leading to cautious behavior and negative sentiment.
Speculation Analysis
Key Takeaways
- SparkKitty malware infiltrated official app stores, scanning photo libraries for crypto wallet seed phrases.
- iOS app “币coin” and Android app SOEX (10,000+ installs) were trojanized, exfiltrating screenshots.
- Unlike clipboard grabbers, SparkKitty targets image storage directly, making seed phrase screenshots a critical risk.
- Affected apps have been removed; researchers warn against storing recovery phrases as images.
What Happened
A stealthy malware campaign dubbed SparkKitty has been caught lurking inside Apple’s App Store and Google Play, turning legitimate-looking apps into seed phrase thieves. Disguised as crypto tools and messaging platforms, the trojanized apps requested photo library access and then scanned for images containing wallet recovery phrases. Check Point’s July 2026 report details how the malware, first uncovered by Kaspersky in June 2025, managed to bypass app store review processes. The offending apps — including “币coin” on iOS and SOEX on Android — have since been removed, but not before potentially exposing users who stored seed phrases as screenshots.
The Numbers
On Android alone, the SOEX app was downloaded more than 10,000 times from Google Play. The iOS app “币coin” cleared Apple’s review by hiding its malicious code, then silently requested photo access. SparkKitty’s technique is direct: it scans image files rather than monitoring clipboards or keystrokes, making screenshots of recovery phrases a prime target. The campaign’s multi-platform reach — official app stores plus third-party marketplaces — gave it a broad attack surface, though exact victim counts remain undisclosed.
Why It Happened
Crypto users often save seed phrases as screenshots for easy access, a practice that’s convenient but catastrophic when photo libraries are compromised. Attackers exploited users’ trust in official app stores, knowing that even security-conscious individuals may relax permissions for seemingly legitimate apps. SparkKitty’s developers embedded the image-scanning capability deep within trojanized apps, evading detection until flagged by security researchers. The incident reflects a growing trend: cybercriminals increasingly tailor attacks to crypto-specific vulnerabilities, and app stores remain a weak link despite their vetting processes.
Broader Impact
The breach of Apple’s and Google’s walled gardens underscores that no platform is immune. For crypto holders, it’s a wake-up call to treat seed phrases like physical gold — never stored digitally, especially as images. For the industry, it highlights an urgent need for app store operators to improve static and dynamic code analysis to catch such threats before they go live. The same technique could resurface in other apps, making it a blueprint for future attacks.
What to Watch Next
- Additional app removals: Security teams may uncover more trojanized apps still hiding in stores.
- Copycat campaigns: SparkKitty’s success could inspire similar image-scanning malware targeting other platforms.
- App store defenses: Expect Apple and Google to tighten review processes in response to the breach.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.