Go to app

Threat Profile: SparkKitty Malware

Published 7/27/2026, 6:02:27 PM

SparkKitty is a critical cross-platform threat specifically designed to automate the theft of cryptocurrency seed phrases from mobile devices. First identified in mid-2025 but active since February 2024, the malware is highly serious because it successfully bypassed the security vetting of both the Apple App Store and Google Play Store [Source: https://securelist.com/sparkkitty-ios-android-malware/116793/].

The malware's primary innovation is its use of Optical Character Recognition (OCR) to scan a user's entire photo gallery for screenshots or photos of recovery phrases, making it a direct threat to any user who has digitally backed up their keys as an image [Source: https://www.kaspersky.com/blog/ios-android-stealer-sparkkitty/53675/].

Threat Profile: SparkKitty Malware

MetricDetails
Target PlatformsiOS and Android
Primary MechanismOCR-based image scanning for mnemonic phrases
Known Malicious Apps币coin (iOS), SOEX (Android)
Infection Scale10,000+ downloads for SOEX alone [Source: https://kaspersky.com/blog/ios-android-stealer-sparkkitty/53675/]
Persistence LevelHigh (uses Xposed modules on Android; Enterprise Profiles on iOS)
SeverityCritical

Technical Mechanism of Compromise

SparkKitty operates by gaining access to the device's photo library. Once granted permission—often under the guise of a legitimate crypto-tracking or social app—it executes the following:

Scope and Scale

The threat is global, though it has specifically targeted users of Chinese-language crypto tools and social media clones.

Severity Assessment

The risk is extreme for mobile users who store seed phrases in their "Photos" or "Screenshots" folders. Because the malware can operate in the background and exfiltrate data to remote servers, a compromise can occur months before a user notices their funds have been moved.

Security researchers recommend that any user who has installed the "币coin" or "SOEX" apps immediately migrate their assets to a new wallet address generated on a clean device, as the original seed phrase must be considered compromised [Source: https://securelist.com/sparkkitty-ios-android-malware/116793/].

In summary, SparkKitty is a sophisticated, active threat that exploits the common but insecure habit of taking screenshots of seed phrases. Its ability to infiltrate official app stores makes it significantly more dangerous than typical "sideloaded" malware.