SparkKitty turns phone photos into a crypto wallet security risk

1 week ago 11



A mobile spyware campaign known as SparkKitty has returned to attention after reports warned that infected iOS and Android apps can expose crypto wallet recovery phrases stored in phone galleries. Summary SparkKitty steals gallery images, seeking wallet seed phrases, passwords and other sensitive information stored digitally. Malicious iOS and Android apps reached official stores, while sideloaded versions expanded the campaign further. Researchers advise offline seed storage, limited photo permissions and immediate wallet migration after suspected exposure. The malware gains photo access, collects images and sends them to attacker-controlled servers. However, this is not a newly discovered July 2026 threat. Kaspersky published a technical report on June 23, 2025, after finding SparkKitty in Apple’s App Store, Google Play and unofficial channels. A recent Cyberint article has renewed attention around the same malware family. SparkKitty campaign dates back to 2024 Kaspersky linked SparkKitty to SparkCat, an earlier mobile stealer that used optical character recognition to search screenshots for wallet seed phrases. SparkKitty used related delivery methods, but many samples uploaded ...

Read Entire Article