A malware strain aimed at cryptocurrency users has been identified in apps distributed through Apple’s App Store, Google Play, and third-party Android marketplaces, according to a report citing cybersecurity firm Check Point. The malware, known as SparkKitty, is designed to search images stored on infected devices for wallet recovery phrases.

How the malware worked

Check Point said SparkKitty used optical character recognition, or OCR, to scan photos and screenshots saved on a device. Its purpose was to locate cryptocurrency wallet recovery phrases, also called seed phrases, which can be used to regain access to a wallet.

The malware did not stop at seed phrases. According to the report, it also extracted passwords and QR code data from images. That information, along with basic device details, was then transmitted to servers controlled by attackers.

Distribution across app stores

SparkKitty was reportedly spread through several channels rather than a single rogue app source. Check Point said samples were found in Apple’s App Store, Google Play, and third-party Android app stores.

On iOS, the malware was embedded in an App Store-listed crypto-related application called Bcoin. On Android, it was identified in an app named SOEX, which was presented as a messaging and crypto trading platform. The Android app was downloaded more than 10,000 times before it was removed from Google Play.

Apps used as disguises

The report said SparkKitty was hidden inside applications presented as crypto tools, messaging services, and entertainment apps. After installation, the malware requested access to the user’s photo library. Once permission was granted, it continuously scanned both existing images and new photos added later.

That behavior made image-based storage of sensitive wallet information especially risky. A recovery phrase by itself is enough to provide full access to a crypto wallet, meaning anyone who obtains it can take control of the funds associated with that wallet.

Link to earlier malware

Check Point described SparkKitty as an apparent evolution of SparkCat, an earlier information-stealing malware strain that also relied on OCR to collect data from screenshots. The newer strain appears to follow the same broad method while targeting cryptocurrency-related information stored in device image galleries.

The finding underlines a recurring security weakness for crypto users who keep seed phrases in photos or screenshots on their phones. In this case, the reported theft vector depended on image access and OCR, rather than direct compromise of a wallet app itself.

Source: en.bloomingbit.io