Resurgence of SparkKitty Mobile Spyware
Recent alerts have brought to light the resurgence of the mobile spyware known as SparkKitty, which has been linked to the unauthorized access of cryptocurrency wallet recovery phrases stored in phone galleries on both iOS and Android platforms. This malware stealthily collects access to photos, gathering images and transmitting sensitive data to servers controlled by malicious actors.
Background and Evolution
Though this threat is not new, as Kaspersky had already identified SparkKitty in its June 2025 technical report, attention has rekindled due to a recent article by Cyberint focusing on this spyware family. SparkKitty is associated with a previous variant called SparkCat, which utilized optical character recognition (OCR) technology to sift through screenshots for cryptocurrency wallet seed phrases. Unlike its predecessor, SparkKitty often uploads entire photo gallery images instead of selectively targeting files that contain relevant recovery information.
Current Threat Landscape
In a new announcement, cybersecurity firm Check Point alerted users about the presence of SparkKitty in mobile applications that consistently scan photo libraries in search of cryptocurrency wallet credentials. If these seed phrases are captured within screenshots, users may be at risk of losing access to their digital assets.
Further investigations revealed connections between SparkKitty and another malicious cohort employing OCR to identify specific images. The implications of this malware extend beyond cryptocurrencies, potentially compromising passwords, identity documents, and QR codes as well. Although Kaspersky suspects that the main objective of SparkKitty is to target crypto assets, they acknowledge that definitive evidence is still lacking.
Operational History
This malware campaign has been operational since at least February 2024, predominantly affecting users in Southeast Asia and China. According to previous reports from crypto.news in June 2025, SparkKitty has proliferated through various channels, including fraudulent cryptocurrency tools and modified social applications.
Milestones in the campaign’s evolution include Kaspersky’s discovery of a new version of SparkCat in April 2026, embedded within applications found on both the Apple App Store and Google Play. This finding indicated that the use of OCR for gallery theft was still a tactic in play, although it did not confirm the reemergence of SparkKitty itself.
Technical Insights
On the iOS front, researchers identified malicious code nestled within altered frameworks designed to mimic well-known development libraries like AFNetworking and Alamofire. Other instances concealed their payloads in an obfuscated file named libswiftDarwin.dylib. Once launched, the malware connects to remote infrastructure to gain access to the photo gallery, uploading files that had not previously been compromised. It is also capable of gathering newly added images.
For Android users, SparkKitty has manifested in both Java and Kotlin versions, with some variants functioning as Xposed modules on rooted devices. As the malware connects to command servers, it transfers images along with the infected device’s details. This method contrasts with traditional malware that solely records keystrokes or manipulates clipboard data.
Recent Findings and Recommendations
In their findings, Kaspersky also noted an Android messaging app with cryptocurrency exchange capabilities present in the Play Store, which attracted over 10,000 downloads before being removed following Kaspersky’s alert. An iOS app called 币coin was similarly flagged and removed from Apple’s App Store after the same investigation.
The malware has also infiltrated through counterfeit websites, modified TikTok applications, gambling apps, and direct Android package installations. Some campaigns targeting iPhone users exploited enterprise provisioning tools meant for internal app distribution.
While the latest reports have elevated concerns surrounding SparkKitty, it’s crucial to recognize that the history of this malware dates back to Kaspersky’s disclosures in 2025, rather than as a newfound threat discovered in July 2026. Moreover, there are no confirmed statistics on the number of victims or financial losses sustained due to this spyware.
Protective Measures
Seed phrases, typically consisting of a dozen or twenty-four words, hold the key to restoring a self-custody wallet, making it imperative for users to safeguard them. Users are advised against storing seed phrases in screenshots, cloud storage, or app notes. Instead, the crypto community recommends permanently recording these phrases in paper or metal formats kept securely offline.
For any user suspecting that SparkKitty may have accessed their seed phrase, it is essential to create a new wallet on a secure device and transfer any remaining assets promptly. Following this, they should uninstall the suspicious application, update their device, and change credentials that might have been saved in compromised image files. Rigorous scrutiny of app permissions and avoiding alternate download sources can help mitigate risks associated with this evolving malware threat.