web3: SparkKitty malware infiltrates app stores to steal wallet mnemonic phrases.
Decrypt
07-28 04:42
Ai Focus
A Check Point report claims that SparkKitty, distributed through app stores, scans screenshots of wallet mnemonic phrases in users' photo albums, threatening the security of crypto assets.
Helpful
No.Help

Security firm Check Point has released a report stating that malware called SparkKitty is stealing encrypted user information through mobile applications. Its main method is not to listen to the clipboard or record keystrokes, but rather, after user authorization, it directly scans the phone's photo album, searching for screenshots of wallet mnemonic phrases and other content, and then uploads the data to a server controlled by attackers.

Appearing in both major app stores

The report indicates that SparkKitty was first discovered by Kabasa in June 2025. Check Point further traced its propagation path, stating that the malware appeared on the Apple App Store, Google Play, and multiple third-party app stores, covering both iPhone and Android devices.

Researchers point out that this type of distribution expands the attack surface. The apps often disguise themselves as legitimate encryption tools, communication platforms, or even entertainment applications to increase the likelihood of downloads and installations.

Start scanning after granting access to the photo album.

On iOS, researchers reported that a crypto app called "Coin" was listed on the Apple App Store and bypassed review by hiding malicious code before requesting access to the user's photo library. On Android, the malware appeared in a communication and crypto trading app called SOEX.

  • SOEX was downloaded more than 10,000 times before it was removed from app stores.
  • Other variants can also be found in third-party stores and side-loaded APKs.
  • Disguise includes fake TikTok and gambling apps.

Taking screenshots of mnemonic phrases carries higher risks.

Unlike common information theft programs, SparkKitty directly searches user-saved images, making the practice of saving wallet recovery phrases in screenshots even riskier. Once the relevant images are identified and uploaded, attackers could potentially gain control of the wallet and subsequently transfer assets.

This report comes amid a series of malware attacks targeting crypto users. In March, Google disclosed that DarkSword, using blockchain technology, deployed Ghostblade malware, targeting major crypto exchanges and wallet applications, and capable of stealing data such as messages, passwords, and photos.

Additional information:In the same month, the FBI also launched an investigation into several games distributed through Valve's Steam platform after malware was found to be installed, including games such as Chemia, PirateFi, and Tokenova.

Tip
$0
Like
0
Save
0
Views 506
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Apple faces $1.835 million lawsuit over fake Bitcoin wallet app.
Three users have filed a lawsuit against Apple, alleging that a fake Sparrow Wallet app on the App Store caused them to lose approximately $1.835 million in Bitcoin. The case has been filed in a U.S. federal court.
crypto.news
·2026-07-28 17:12:25
378
Web3: India demands the removal of Bitchat, an app associated with Jack Dorsey.
India has demanded that GitHub remove the Bitchat-related code repository, claiming that its anonymous communication and offline Bitcoin transaction features hinder law enforcement.
CoinDesk
·2026-07-24 18:18:39
987
Web3: Samsung Wallet plans to add stablecoin functionality.
Samsung plans to add stablecoin support to Samsung Wallet, but has not yet disclosed the currency, timeline, or partners.
crypto.news
·2026-07-24 19:18:54
435
Web3: Apple sued for failing to remove counterfeit Bitcoin wallets from its App Store
Apple is being sued for failing to promptly remove counterfeit Bitcoin wallet apps from the App Store; the three plaintiffs claim a combined loss of approximately $1.84 million.
CoinDesk
·2026-07-28 20:12:57
173
Web3: Counterfeit wallets appear on the App Store; Apple faces $1.8 million lawsuit.
Three users who lost $1.8 million in Bitcoin due to a fake Sparrow Wallet have sued Apple in California.
Coinpedia
·2026-07-28 09:11:16
263