Close Menu
InclusiFund
    What's Hot

    She Code Africa marks 10 years, now focused on tech leadership for African women

    September 21, 2026

    X sues crypto operators for £207,000 over alleged creator revenue fraud

    September 21, 2026

    iOS 27 Adds Impersonation Risk Detection to Help Protect Against Social Engineering Scams

    September 21, 2026
    Facebook X (Twitter) Instagram
    InclusiFund
    Facebook X (Twitter) Instagram
    • Home
    • Daily Brief
    • Dealflow Dashboard
    • Sectors
      • Agritech
      • Climate Tech
      • Fintech
      • Healthtech
      • Logistics
      • Mobility
      • SaaS / Enterprise
    • Tools
    • Reports
    • Opinion
    • Services
      • For Investors
      • For Founders
    • About Us
    • More
      • Disclaimer
      • Advertise With Us
      • Newsletter
      • Work With Us
      • Terms and Conditions
      • Privacy Policy
      • Contact Us
      • About Us
    InclusiFund
    Home»Crypto»SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases
    Crypto

    SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases

    ElanBy ElanJuly 27, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
    SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    In brief

    • SparkKitty scanned users’ photo libraries for crypto wallet seed phrases and other sensitive information.
    • The malware was distributed through malicious apps on Apple’s App Store, Google Play, and third-party app stores.
    • Researchers warn that storing wallet recovery phrases as screenshots can expose crypto assets to theft.

    A new report from cybersecurity firm Check Point details how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases and other sensitive information.

    First discovered by Kaspersky in June 2025, Check Point’s analysis detailed how the malware spread through Apple’s App Store, Google Play, and third-party app stores.

    “What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface,” Check Point wrote. “The threat actor behind SparkKitty distributed trojanized applications disguised as legitimate cryptocurrency tools, messaging platforms, and even entertainment apps—greatly increasing the likelihood of installation by unsuspecting users.”

    After users granted access to their photo libraries, the malware scanned stored images for wallet recovery phrases and other sensitive information before uploading the data to attacker-controlled servers.

    On iOS, SparkKitty was distributed through a cryptocurrency app called “币coin” that was available on Apple’s App Store. Check Point said the app concealed its malicious code to evade Apple’s review process before requesting access to users’ photo libraries. On Android, the malware appeared in a messaging and cryptocurrency exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before being removed. Other variants were distributed through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APKs.

    Unlike many information stealers that rely on clipboard monitoring or keylogging, SparkKitty searched users’ photo libraries directly, making screenshots of wallet recovery phrases a prime target.

    Researchers recommend keeping wallet recovery phrases offline instead of storing them as screenshots, limiting photo library permissions to trusted apps, and downloading software only from reputable developers.

    The report follows a string of malware campaigns targeting cryptocurrency users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet apps while stealing messages, passwords, photos, and other data from vulnerable iPhones. That same month, the FBI launched an investigation after several games distributed through Valve’s Steam platform—including “Chemia,” “PirateFi,” and “Tokenova”—were found to install malware.

    In May, AI startup Perplexity open-sourced Bumblebee, a security tool designed to detect compromised software packages, browser extensions, and AI connector configurations without executing potentially malicious code following a software supply-chain attack that affected more than 160 developer packages.

    In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. The campaign deployed Lumma and Vidar infostealers, malware commonly used to steal browser credentials and cryptocurrency wallet data.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    app Crypto Malware Phrases Seed SparkKitty Stores targets wallet
    Elan
    • Website

    Related Posts

    She Code Africa marks 10 years, now focused on tech leadership for African women

    September 21, 2026

    X sues crypto operators for £207,000 over alleged creator revenue fraud

    September 21, 2026

    Visa Moves to Close Meme Coin Credit Card Rewards Loophole

    September 20, 2026
    Leave A Reply Cancel Reply

    Economy News
    Crypto

    She Code Africa marks 10 years, now focused on tech leadership for African women

    By ElanSeptember 21, 20260

    After a decade focused on expanding women’s access to technology, She Code Africa is placing…

    X sues crypto operators for £207,000 over alleged creator revenue fraud

    September 21, 2026

    iOS 27 Adds Impersonation Risk Detection to Help Protect Against Social Engineering Scams

    September 21, 2026
    Top Trending
    Crypto

    She Code Africa marks 10 years, now focused on tech leadership for African women

    By ElanSeptember 21, 20260

    After a decade focused on expanding women’s access to technology, She Code…

    Tech

    X sues crypto operators for £207,000 over alleged creator revenue fraud

    By ElanSeptember 21, 20260

    Before now, the worst penalty a social media platform could hand down…

    Tools

    iOS 27 Adds Impersonation Risk Detection to Help Protect Against Social Engineering Scams

    By ElanSeptember 21, 20260

    Apple has included a scam prevention feature known as Impersonation Risk Detection…

    Your source for comprehensive insights on Africa’s private credit markets, InclusiFund synthesizes deal pipelines, repayment patterns, collateral trends, and sector-level signals to guide investors in underwriting and structuring credit in emerging African markets.

    We're social. Connect with us:

    our Categories
    • Work With Us
    • Advertise With Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Work With Us
    • Advertise With Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 Inclusifund. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.