July 27, 2026 ChainGPT

SparkKitty mobile spyware exfiltrates phone photos to steal wallet seed phrases

SparkKitty mobile spyware exfiltrates phone photos to steal wallet seed phrases
Your photos could give attackers full access to your crypto — meet SparkKitty, the mobile spyware hunting wallet seed phrases in phone galleries. What SparkKitty does - SparkKitty is a mobile stealer that requests photo access, scans and uploads images from infected iOS and Android devices to attacker-controlled servers. If a screenshot or photo contains a wallet recovery phrase (the 12- or 24-word “seed”), an attacker can recreate the wallet and drain its funds. - Some samples indiscriminately exfiltrated whole galleries; others used OCR (optical character recognition) to pick images likely to contain seed phrases, passwords, identity documents or QR codes. Origins and timeline - This is not a brand-new July 2026 threat. Kaspersky published a technical report on June 23, 2025 after finding SparkKitty in Apple’s App Store, Google Play and third-party channels. Kaspersky linked SparkKitty to an earlier family called SparkCat, which used OCR to search screenshots for seed phrases. - Kaspersky’s investigation found the campaign had been active since at least February 2024, largely targeting Southeast Asia and China. Distribution vectors included fake crypto tools, modified social apps, gambling apps, fake websites, modified TikTok clients, direct APKs and sideloaded enterprise apps. - In April 2026 Kaspersky reported a new SparkCat variant in two App Store apps and one Google Play app; those samples continued to use OCR-based gallery theft. Recent media attention in July 2026 has renewed warnings but does not demonstrate a newly discovered campaign separate from Kaspersky’s 2025 disclosures. Technical notes (high level) - On iOS, malicious code was hidden in modified frameworks imitating common libraries (AFNetworking, Alamofire), in an obfuscated libswiftDarwin.dylib, or embedded directly in apps. After launch, the malware contacted command-and-control servers, asked for photo permissions, then monitored and uploaded images — including new photos. - On Android, samples appeared in Java and Kotlin, and some ran as Xposed modules on rooted devices. Exfiltrated images were sent alongside device and app metadata. - This photo-based approach differs from clipboard “clipper” malware that intercepts copied wallet addresses; both pose serious threats to self-custodial wallet holders. Notable takedowns and scope - Kaspersky flagged a Google Play messaging app with exchange features called SOEX; it had over 10,000 installs before Google removed it. An iOS app named 币coin was also removed from the App Store after Kaspersky alerted Apple. Researchers did not determine whether developers knowingly included the malware. - The public record does not include a confirmed victim count or total crypto losses. Original malicious listings were removed, but sideloaded copies and modified apps may still circulate. Why seed phrases matter - A seed phrase (typically 12 or 24 words) can restore every private key in a self-custody wallet. Anyone who gets those words can recreate and empty the wallet. Changing an app password does not protect an exposed recovery phrase. Practical guidance - Never store seed phrases in screenshots, cloud photo albums, email drafts or notes apps. - Prefer offline storage: write seeds on paper or record them on metal and keep them in a secure physical location (see crypto.news 2026 wallet guide). - Audit app permissions and revoke photo access for apps that don’t need it. - Avoid unofficial app stores, modified apps and unknown download links. Even apps in official stores merit checking the developer and requested permissions. - If you suspect your seed was exposed: create a new wallet on a clean device, move remaining assets immediately, remove the suspected app, update the device OS/apps, and rotate any credentials that may have been stored in gallery images. Bottom line Recent articles have revived attention to SparkKitty, but the primary technical disclosures trace back to Kaspersky’s June 2025 research. Still, the threat is real: mobile photo galleries can be a backdoor to your crypto. Protect your seed phrases and minimize app permissions to reduce the risk. Read more AI-generated news on: undefined/news