Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Hot Topics » News » SparkKitty malware steals photos containing crypto seed phrases
    The SparkKitty malware has been scanning the photo galleries of iOS and Android users for crypto seed phrases since at least February 2024.

    SparkKitty malware steals photos containing crypto seed phrases

    0
    By Editorial Office CVJ.CH on 29. July 2026 News

    Since at least February 2024, the SparkKitty malware has been pulling photos from the galleries of iOS and Android users. It hunts for seed phrases saved as images. In April 2026, Kaspersky reported a new SparkCat variant that detects English-language recovery phrases for the first time.

    SparkKitty and SparkCat are malicious programs that hide inside seemingly harmless mobile apps. After installation, they access the photo gallery and upload stored images to external servers. The target is screenshots of wallet recovery phrases. Instead of keeping them on paper, many users store them on the phone. Kaspersky first described SparkCat in early 2025. The security vendor classified that campaign as the first known OCR trojan in the Apple App Store. Its SparkKitty report followed later, in June 2025. Yet that campaign had been running since at least February 2024. Infected applications originally included the app "币coin" in the Apple App Store and the messenger "SOEX" on Google Play. Apple and Google have since removed both applications.

    Subscribe to our newsletter

    The best articles of the week, directly delivered into your mailbox.

    New SparkCat variant targets English-speaking users for the first time

    Kaspersky reported the new variant in April 2026, more than a year after SparkCat first surfaced. It appeared on the Apple App Store and Google Play at the same time. On Android, it affected the app "SafeX" in version 2.1.0, which ran under the package name com.ekhizc.carterocourrier. In the Apple App Store, analysts found two further applications, "SafeW - 云办公助理" and "悟空外卖: 泰国华人生活管家". The Android variant also hides its code behind code virtualization. Moreover, cross-platform programming languages make analysis harder.

    What matters most, however, is the choice of languages. The Android variant still searches for Japanese, Korean and Chinese keywords. On iOS, in contrast, the malware scans for English-language mnemonic phrases for the first time. A single phrase is enough to restore a wallet on any device. That points to a possible expansion of the target audience beyond Asia.

    The number of users who installed the affected apps remains unclear. So far, reliable installation figures exist only for the earlier wave. Nevertheless, the finding carries weight, because the campaign passed the review processes of both stores once again.

    How the SparkKitty malware scans photos for seed phrases

    The name suggests a targeted search. Yet most SparkKitty variants work crudely and upload every image in the gallery, regardless of content. The analysis happens only at the attackers' end. A related activity cluster, however, proceeds more selectively and uses text recognition from Google ML Kit. As a result, this cluster uploads only images with at least three lines of text. Each line must contain one word of three letters or more.

    SparkCat, in contrast, relies on OCR throughout and searches directly for mnemonic phrases. The two campaigns thus differ mainly in their degree of automation. The disguise follows the platform in each case. On iOS, the malicious code sits in fake network frameworks such as AFNetworking and Alamofire. In addition, a file named libswiftDarwin.dylib poses as a system library. On Android, it runs through malicious modules for Xposed or LSPosed.

    The operators encrypt only the configuration of their control servers, using AES-256-ECB. They stored that configuration on Aliyun OSS and on Gitee, the Chinese counterpart to GitHub. Kaspersky also identified several command-and-control servers. Because the affected apps still delivered their advertised function, the photo leak rarely stood out in everyday use.

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Bitcoin in 2026 trades around USD 84,000, while US spot ETFs hold about USD 102 to 104 billion and listed companies 1.27 to 1.29 million BTC. Background

    Bitcoin in 2026: what the numbers actually say

    Financial Products

    Memecoins on Robinhood Chain distort tokenized stock prices

    Basics

    Unit bias in crypto: Why cheap coins mislead investors

    Ray Dalio advises 10 to 15% gold and a small Bitcoin position, because he expects a US debt crisis within about three years. Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Bitcoin in 2026 trades around USD 84,000, while US spot ETFs hold about USD 102 to 104 billion and listed companies 1.27 to 1.29 million BTC. Background

    Bitcoin in 2026: what the numbers actually say

    Disguises in app stores and TikTok clones

    "币coin" appeared in the Apple App Store as an information service for crypto prices. "SOEX", meanwhile, is a messenger with trading features that reached more than 10,000 installations on Google Play. Apple and Google removed the applications after Kaspersky's report. Google confirmed the removal and banned the developer.

    Outside the official stores, SparkKitty also spread through modified TikTok clones with fake crypto shops. Other carriers included gambling apps, casino offerings and adult games. On iOS, attackers further used enterprise provisioning profiles. Companies use these profiles for internal app distribution. That route therefore bypasses the store entirely. The picture with SparkCat looked similar in early 2025. Kaspersky found two infected apps in the Apple App Store back then and one on Google Play. There, the malicious function hid in corporate messengers and in food delivery apps.

    Both campaigns initially targeted Asia, with SparkKitty focused on China and Southeast Asia. Moreover, Kaspersky links the two campaigns through jointly infected Android apps and matching debug symbols in the iOS frameworks. The company suspects a Chinese-speaking threat actor behind SparkCat. Yet both campaigns passed store review, which puts the protective value of that review into perspective.

    Protection against seed phrase theft from the gallery

    The most effective measure is the simplest one. A seed phrase therefore does not belong in a phone's gallery as a photo or screenshot. Anyone who already holds such images should delete them, or at least move them to encrypted offline storage. Hardware wallets keep the phrase off the smartphone permanently.

    Similarly, a look at app permissions helps. A price tracker or a messenger rarely needs full access to the entire photo library. Official stores nevertheless remain the better choice over third-party sources. But they guarantee no protection, as the "币coin" and "SOEX" cases show. Consequently, users should check developer reputation and permission requests before installing.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH
    Editorial Office CVJ.CH
    • Website
    • X (Twitter)
    • LinkedIn

    Since 2018, the editorial team at Crypto Valley Journal has been reporting from Zug - the heart of Switzerland’s Crypto Valley - on Bitcoin, cryptocurrency, blockchain, and regulatory developments in digital assets. Behind the publication’s collective editorial voice is a team of writers with backgrounds in financial markets, law, and technology.

    Related Articles

    About 600 BTC are still missing from Blockstream's Liquid Network reserve after the hack, and a USD 4 billion deal from Adam Back's circle collapsed.

    Adam Back’s Blockstream fights for USD 50 million after Liquid hack

    Armada shareholders vote on the Evernorth merger on September 30, and the XRP treasury would then list on the Nasdaq under the ticker XRPN.

    XRP treasury: Evernorth Nasdaq listing moves closer

    CVJ weekly review

    Weekly review: Early signals suggest a Bitcoin bull market

    Comments are closed.

    About 600 BTC are still missing from Blockstream's Liquid Network reserve after the hack, and a USD 4 billion deal from Adam Back's circle collapsed.
    30. September 2026

    Adam Back’s Blockstream fights for USD 50 million after Liquid hack

    According to a US Senate report, 84% of 846 Iran-linked wallets used almost only USDT, while Tether cites nearly USD 550 million in freezes.
    29. September 2026

    US senator seeks probes into Tether over Iran wallets

    Bitcoin in 2026 trades around USD 84,000, while US spot ETFs hold about USD 102 to 104 billion and listed companies 1.27 to 1.29 million BTC.
    29. September 2026

    Bitcoin in 2026: what the numbers actually say

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.