A malware campaign known as SparkKitty successfully infiltrated both Apple's App Store and Google Play, targeting cryptocurrency users by scanning their photo libraries for wallet recovery phrases and other sensitive information. The campaign, detailed in a new report by cybersecurity firm Check Point, highlights an often-overlooked vulnerability in how digital asset owners protect their keys.

First discovered by Kaspersky in June 2025, SparkKitty represents a departure from the typical information-stealing malware paradigm. Rather than relying on clipboard monitoring or keylogging — techniques that security software has become increasingly adept at detecting — the malware went directly after users' photo libraries, where many crypto holders store screenshots of their recovery phrases for convenience.

How It Spread

SparkKitty was distributed through trojanized applications disguised as legitimate tools. On iOS, the malware was embedded in a cryptocurrency app called "币coin" that passed Apple's app review process. On Android, it appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before removal.

Additional variants were distributed through third-party app stores, fake TikTok applications, gambling apps, and sideloaded APKs — broadening the attack surface across platforms and user demographics.

"What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface," Check Point wrote. "The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps."

The Photo Library Problem

The core exploit relies on a simple but widespread behavioral pattern. Despite years of guidance from wallet developers and security experts, a significant number of cryptocurrency users continue to store screenshots of their recovery phrases on their devices. This practice transforms a seed phrase — designed to be memorized or written on physical paper — into a digital artifact that any app with photo library access can read.

Once a user granted photo permissions to a SparkKitty-infected app, the malware systematically scanned stored images for wallet recovery phrases and other sensitive data, then uploaded the results to attacker-controlled servers. The approach is elegantly simple and devastatingly effective against the specific demographic it targets.

A Broader Trend

SparkKitty is the latest in an escalating series of malware campaigns targeting cryptocurrency users through seemingly legitimate software channels:

  • DarkSword (March 2026): An exploit chain deploying Ghostblade malware capable of targeting major crypto exchanges and wallet apps on unpatched iPhones.
  • Steam gaming malware (March 2026): Several games distributed through Valve's Steam platform installed information-stealing malware, prompting an FBI investigation.
  • Bumblebee (May 2026): Perplexity open-sourced a security tool to detect compromised software packages and AI connector configurations after a supply-chain attack hit more than 160 developer packages.
  • Wallpaper Engine (June 2026): Attackers used Steam Workshop to distribute malware disguised as anime-themed wallpapers, deploying Lumma and Vidar infostealers to steal browser credentials and crypto wallet data.

The pattern reveals an industry-wide vulnerability: the same distribution channels that make software accessible to legitimate users — app stores, gaming platforms, developer repositories — are increasingly exploited to reach cryptocurrency holders. The economics are straightforward. A single successfully stolen seed phrase can grant access to wallets containing thousands or millions of dollars in digital assets, and unlike a credit card number, a compromised seed phrase cannot be frozen or reversed.

Recommendations

Security researchers emphasize three practices: store wallet recovery phrases offline, never as digital screenshots; limit photo library permissions to genuinely trusted applications; and download software exclusively from reputable developers with established track records. For users who have stored seed phrase images on their devices, the guidance is to move those funds to a new wallet immediately — the original phrase should be considered compromised.

As cryptocurrency adoption grows, the incentives for attackers will only intensify. SparkKitty demonstrates that the gap between user convenience and security remains the most exploitable vulnerability in the ecosystem.