According to security firm Check Point, on July 27, SparkKitty malware was discovered embedded across iOS and Android applications on Apple App Store, Google Play, and third-party Android stores. The cross-platform malware family uses optical character recognition (OCR) to scan photos in user galleries and extract cryptocurrency wallet seed phrases, passwords, and QR codes, then uploads the stolen data along with device information to remote servers.
Attackers disguised SparkKitty as crypto services, chat tools, and entertainment apps, requesting gallery access before continuously scanning existing and new photos. Identified samples include the "CoinCoin" app on iOS and "SOEX" app on Android, which exceeded 10,000 downloads before removal. Additional variants have spread through third-party stores, modified TikTok versions, and gambling apps, with some maintaining persistence on rooted devices via Xposed modules. Check Point advises users to store seed phrases offline, avoid taking screenshots or photos of recovery phrases, and regularly review app camera and gallery permissions.