A cross-platform mobile spyware campaign named SparkKitty is raising alarms across the crypto community after security researchers confirmed it can extract wallet recovery phrases directly from smartphone photo galleries. First detailed by Kaspersky in June 2025, the malware reappeared in public attention in July 2026, though no new variant has been confirmed—only renewed warnings.
SparkKitty infiltrates both iOS and Android devices through apps disguised as legitimate crypto tools, messaging platforms, or modified social media clients. Some of these apps even made their way into Apple’s App Store and Google Play, with one Android messaging app called SOEX accumulating over 10,000 installs before removal. Once installed, the malware requests access to the photo library. If granted, it systematically uploads images to attacker-controlled servers, hunting for screenshots that contain wallet seed phrases, passwords, identity documents, or QR codes.
Kaspersky’s June 2025 report linked SparkKitty to an earlier stealer named SparkCat, which used optical character recognition (OCR) to specifically filter images containing recovery phrases. SparkKitty sometimes uses similar OCR techniques, but many observed samples simply exfiltrated entire galleries rather than selecting targeted files. The campaign is believed to have been active since at least February 2024, primarily targeting users in Southeast Asia and China.
On iOS, the malware hid inside modified frameworks mimicking common development libraries like AFNetworking and Alamofire, or inside obfuscated files named libswiftDarwin.dylib. On Android, it appeared in Java and Kotlin variants, with some samples operating as Xposed modules on rooted devices. In April 2026, Kaspersky reported a fresh SparkCat variant in two App Store apps and one Google Play app, confirming continuing OCR-based gallery theft, though not necessarily SparkKitty itself.
The danger is critical for anyone who stores seed phrases digitally. A seed phrase—typically 12 or 24 words—can reconstruct an entire self-custody wallet and transfer all assets. No password change can protect an exposed phrase. Researchers strongly advise offline storage (paper or metal), revoking unnecessary photo permissions, and immediately migrating wallets on a clean device if exposure is suspected.