Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Wallets

SparkKitty Scans Photos to Steal Crypto Wallet Seed Phrases

2 reports · First detected 2026-07-27 · Last active 2026-07-28

SparkKitty is a cross-platform mobile malware campaign aimed at cryptocurrency users on iOS and Android. It is described as an evolution of SparkCat, an earlier stealer that used optical character recognition to read text in images. After gaining photo-library access, SparkKitty searches screenshots for wallet recovery seed phrases, passwords and QR codes. A stolen seed phrase can let an attacker restore and control a self-custodied wallet from another device, bypassing protections on the victim’s phone.

Check Point said in a report published July 26, 2026, that SparkKitty had reached Apple’s App Store, Google Play and third-party Android marketplaces. On iOS, researchers found it inside a cryptocurrency app called “币coin”; on Android, it appeared in SOEX, presented as a messaging and crypto-exchange platform. SOEX exceeded 10,000 Google Play downloads before removal. The malware also circulated through sideloaded APKs, modified TikTok apps and gambling services, transmitting extracted text and device data to attacker-controlled servers.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)