SparkKitty Malware Harvests Crypto Wallet Seed Phrases from App Stores
A new mobile threat named SparkKitty is targeting cryptocurrency users on both iOS and Android devices. The malware obtains permission to access the photo gallery, then uses optical character recognition to scan images for wallet recovery (seed) phrases stored in screenshots or photos. When a seed phrase is found, the data are sent to remote servers, allowing attackers to empty the associated crypto wallets.
Check Point researchers identified the campaign spreading through legitimate‑looking apps that were accepted onto the Apple App Store and Google Play. On iOS, the malicious app was listed as “币coin,” while the Android version appeared as “SOEX,” a messaging and exchange‑style app that accumulated more than 10,000 downloads before removal. SparkKitty is an evolution of the earlier SparkCat stealer.
The threat highlights the danger of storing seed phrases in digital form. Security experts advise keeping recovery words offline, using hardware wallets, and limiting photo‑library permissions to only essential applications.
Entities: Check Point · SOEX · SparkKitty · 币coin