Security firm Check Point has released a report stating that malware called SparkKitty is stealing encrypted user information through mobile applications. Its main method is not to listen to the clipboard or record keystrokes, but rather, after user authorization, it directly scans the phone's photo album, searching for screenshots of wallet mnemonic phrases and other content, and then uploads the data to a server controlled by attackers.
Appearing in both major app stores
The report indicates that SparkKitty was first discovered by Kabasa in June 2025. Check Point further traced its propagation path, stating that the malware appeared on the Apple App Store, Google Play, and multiple third-party app stores, covering both iPhone and Android devices.
Researchers point out that this type of distribution expands the attack surface. The apps often disguise themselves as legitimate encryption tools, communication platforms, or even entertainment applications to increase the likelihood of downloads and installations.
Start scanning after granting access to the photo album.
On iOS, researchers reported that a crypto app called "Coin" was listed on the Apple App Store and bypassed review by hiding malicious code before requesting access to the user's photo library. On Android, the malware appeared in a communication and crypto trading app called SOEX.
- SOEX was downloaded more than 10,000 times before it was removed from app stores.
- Other variants can also be found in third-party stores and side-loaded APKs.
- Disguise includes fake TikTok and gambling apps.
Taking screenshots of mnemonic phrases carries higher risks.
Unlike common information theft programs, SparkKitty directly searches user-saved images, making the practice of saving wallet recovery phrases in screenshots even riskier. Once the relevant images are identified and uploaded, attackers could potentially gain control of the wallet and subsequently transfer assets.
This report comes amid a series of malware attacks targeting crypto users. In March, Google disclosed that DarkSword, using blockchain technology, deployed Ghostblade malware, targeting major crypto exchanges and wallet applications, and capable of stealing data such as messages, passwords, and photos.
Additional information:In the same month, the FBI also launched an investigation into several games distributed through Valve's Steam platform after malware was found to be installed, including games such as Chemia, PirateFi, and Tokenova.











