SparkKitty malware infiltrates App Store and Google Play, targets crypto wallets
In brief
- SparkKitty distributed via 币coin (App Store) and SOEX (Google Play), downloaded 10,000+ times before removal
- Malware scanned device photos for wallet recovery phrases and uploaded stolen data to attacker servers
- Both major app stores provided wide attack surface compared to sideloaded malware variants
- Researchers recommend storing recovery phrases offline instead of as device screenshots
How SparkKitty Spread
Check Point detailed how the malware spread through Apple's App Store, Google Play, and third-party app stores. On iOS, the malware was distributed through a cryptocurrency app called 币coin available on Apple's App Store. On Android, it appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before being removed.
The app concealed its malicious code to evade Apple's review process before requesting access to users' photo libraries. Once granted permission, the malware scanned stored images for wallet recovery phrases and other sensitive information before uploading the data to attacker-controlled servers.
The Threat's Scope
What makes this attack notable is its distribution method. The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.
Other variants were distributed through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs. Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users' photo libraries directly, making screenshots of wallet recovery phrases a prime target.
Defensive Measures
Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots. The presence of SparkKitty on both major app stores underscores how crypto users face threats across multiple distribution channels. Recent months have seen similar targeted attacks—in March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware targeting cryptocurrency exchanges and wallet apps. In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers.
The SparkKitty campaign demonstrates that official app stores remain vulnerable to determined threat actors, even with review processes in place.


