SparkKitty Scans Photos to Steal Crypto Wallet Seed Phrases
SparkKitty is a cross-platform mobile malware campaign aimed at cryptocurrency users on iOS and Android. It is described as an evolution of SparkCat, an earlier stealer that used optical character recognition to read text in images. After gaining photo-library access, SparkKitty searches screenshots for wallet recovery seed phrases, passwords and QR codes. A stolen seed phrase can let an attacker restore and control a self-custodied wallet from another device, bypassing protections on the victim’s phone.
Check Point said in a report published July 26, 2026, that SparkKitty had reached Apple’s App Store, Google Play and third-party Android marketplaces. On iOS, researchers found it inside a cryptocurrency app called “币coin”; on Android, it appeared in SOEX, presented as a messaging and crypto-exchange platform. SOEX exceeded 10,000 Google Play downloads before removal. The malware also circulated through sideloaded APKs, modified TikTok apps and gambling services, transmitting extracted text and device data to attacker-controlled servers.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.