A malware campaign dubbed SparkKitty has been found in apps distributed through both Apple’s App Store and Google Play, according to researchers who said it targeted crypto wallet recovery phrases saved as images on users’ phones. Apple and Google have since removed the affected apps.

How the malware worked

Researchers said SparkKitty focused on a common but risky habit among crypto users: storing wallet backup phrases in their photo libraries. After a user granted an infected app access to photos, the malware scanned images already on the device as well as new images saved later.

The scanning process reportedly used optical character recognition, or OCR, to identify 12-word and 24-word wallet recovery phrases inside screenshots and other saved pictures. If a phrase was detected, the malware was said to transmit the extracted text to attacker-controlled command-and-control servers. Researchers added that basic device details were also sent along with the phrases.

Spread across iOS and Android apps

The campaign affected both iOS and Android devices through apps that appeared in official app marketplaces. Several malicious apps were identified in the App Store and on Google Play before being removed.

Among the apps named by researchers was SOEX, along with other coin-related applications. Some of the infected apps reportedly accumulated thousands of downloads before Apple and Google took them down.

The presence of the malware in official stores is notable because it meant users did not need to sideload software from unofficial sources to be exposed. The campaign instead relied on ordinary app permissions, particularly access to the photo library.

An evolution of an earlier approach

Researchers said SparkKitty represented an evolution of a previous campaign known as SparkCat. In that earlier approach, attackers also used OCR-based methods tied to crypto-related data theft.

In the SparkKitty case, the emphasis was on mining phone photo collections for sensitive wallet backups. Because many recovery phrases are recorded as screenshots or photographed on paper, access to the image library could give attackers a path to wallet control without directly compromising a wallet app itself.

Warnings over fake wallet apps

Public warnings linked to the campaign also pointed to a second tactic: fraudulent wallet applications designed to imitate legitimate products. According to the warnings, attackers used copied logos and small spelling changes in app names to make fake wallets appear authentic.

Researchers cautioned that if a user entered a wallet recovery phrase into one of those counterfeit apps, the attackers could gain access to the wallet. That threat is separate from the image-scanning behavior but follows the same objective of obtaining recovery phrases, which can function as the master key to crypto holdings.

The SparkKitty case underscores a recurring security problem in crypto: recovery phrases remain highly valuable targets, and attackers continue adapting both technical and social methods to capture them. In this instance, the campaign reportedly combined broad mobile app distribution, photo access permissions, OCR scanning, and lookalike wallet branding to pursue that goal.

Source: Coin Edition