Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

SparkKitty Malware Targets Crypto Users Through Apple and Google App Store Loopholes

Author
Raymond Munene
Raymond Munene
Crypto Writer
Fact Checked by Joshua Downes
Last updated: June 24, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
SparkKitty Malware Targets Crypto Users Through Apple and Google App Store Loopholes

Highlights:

  • The SparkKitty crypto malware uses apps in the Google Play and App Store.
  • It applies OCR to scan through image galleries to decode seed phrases.
  • Over 5,000 users installed infected crypto-themed apps.

A new crypto-malware version called SparkKitty exploits mobile users by using malicious apps installed in the official app stores. According to cybersecurity specialists Kaspersky, they have been monitoring this spyware since the beginning of 2024, and cases have been linked with apps posing as crypto tools. The malware aims to gather wallet seed phrase screenshots in user photo libraries.

SparkKitty, which is highly similar to a former version called SparkCat, resorts to visual data scanning to identify sensitive recovery phrases. The malware was found in the applications that pretended to be crypto trackers or gambling devices or modified social media platforms. After the users installed such apps, the malware asked to access the photo gallery and scanned the stored photographs silently.

🚨 SlowMist TI Alert 🚨

A new malware named #SparkKitty that steals all photos from infected iOS & Android devices — searching for crypto wallet seed phrases.

⚠️ Delivered via:
🔸 "币coin" (App Store)
🔸 "SOEX" (Google Play, 10K+ installs, now removed)
🔸 Casino apps, adult… pic.twitter.com/47WDc8l6tQ

— SlowMist (@SlowMist_Team) June 24, 2025

Malware Slips Into Official App Stores

A number of malicious SparkKitty-infected applications passed through the review systems of Google Play and the Apple App Store. In addition, apps such as Soex Wallet Tracker and Coin Wallet Pro received thousands of downloads until they were removed. These applications looked authentic, advertising the ability to track portfolios in real-time or have multi-chain wallet capabilities.

Certain apps encouraged the installation of developer profiles that bypassed the normal security sandbox. The additional step gave the malware wider access to the system. After permissions were allowed, SparkKitty checked the screenshots according to seed phrase patterns. The malware was able to read the images in the form of text with the use of optical character recognition (OCR).

Once valid seed phrases were found, the malware sent them to other servers. These phrases help access and empty crypto wallets completely. The target users of the campaign were based in Southeast Asia as well as China, though it was easy to multiply in other regions. There were no regional limitations within the code used by the malware.

Crypto Malware Targets User Behavior

SparkKitty does not target wallets directly; it uses a popular habit instead. Most users keep the seed phrases in the form of screenshots, which they usually do not realize is dangerous. Though it is convenient, there is a weakness created by this method. Thus, this behavior was used by SparkKitty to scan thousands of photos to obtain sensitive information.

According to Kaspersky analysts, some of the infected apps were TikTok clones, gambling games, and crypto tools. Additionally, this made the malware attractive to users who are present in crypto or social media realms. The promotion of certain apps was placed either via Telegram or social ads, contributing to their reach.

After being installed, SparkKitty waited until certain user actions, such as opening chats or settings, before it requested gallery access. When it was obtained, it scanned galleries in the background. The malware operated silently, and the user could not know about its operations. Furthermore, it processed only the contents of images that were familiar with wallet recovery formats.

App Stores Under Fire After Malware Bypass

After detecting it, Kaspersky notified Apple and Google, who removed the infected apps. The campaign, however, put to question the app store defenses. Allowing the installation of external profiles helped attackers bypass sandbox restrictions designed to limit access.

Prior to their removal, the infected apps are reported to have been downloaded by more than 10,000 users. The security teams are currently keeping an eye on such behaviour in more recent crypto-themed applications. In addition, Kaspersky continues to track SparkKitty’s malware infrastructure and has shared threat data with cyber authorities.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Tags

Apple StoreCrypto malwareGoogle Play StoreKasperskySparkKitty
Raymond Munene
Author

Raymond Munene

Raymond Munene is a crypto content writer who contributes to Crypto2Community. With over three years of experience, he is interested in Bitcoin, Blockchain, and Technical Analysis. Focusing on daily market analysis, his research helps traders and investors alike. His particular interest in cryptocurrency and blockchain aids his audience.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack

Related Articles:

Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Crypto News4 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
Crypto News6 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Crypto News18 hours ago
Chinedu Agbakwusi
By Chinedu Agbakwusi4/10/2026

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack
  • Aethir Halts Bridge Exploit, Caps Losses Below $90K
  • Ethereum Network Activity Hits All-Time High with 1.3M Transactions
  • Hong Kong Issues First Stablecoin Licences to HSBC and Standard Chartered Venture
  • Bitcoin Could Be Quantum Safe Without a Soft Fork, Analyst Says
  • Top Crypto Picks for Today, April 10 – Zcash, Hyperliquid, BNB
  • Japan Approves Bill to Treat Crypto as Financial Instruments
  • Coinbase CEO Backs Treasury Secretary’s Call to Pass the CLARITY Act
  • Hyperliquid Price Outlook – HYPE Gains Strength, $42.15 in Focus
  • Bitmine Uplists to NYSE with 4.8M ETH and a $4 Billion Buyback
  • Best Crypto Gainers Today, April 9 – SIREN, DEXE, JUST
  • Bitcoin Price Holds Near $71K as Iran BTC Toll Plan Raises Uncertainty
  • Bitcoin Depot Loses 50.9 BTC in Wallet Breach Revealed in SEC Filing
  • Ethereum Foundation Offloads 3,750 ETH Worth $8.3M
  • Stablecoin Volumes May Hit $1.5 Quadrillion by 2035: Chainalysis
  • Treasury Secretary Scott Bessent Calls CLARITY Act a National Priority
  • Canary Capital Seeks SEC Approval for Spot PEPE ETF
  • Iran Plans Bitcoin Toll for Laden Oil Tankers Crossing Strait of Hormuz