00:00
The Financial Ways
The Financial Ways
USD/RUB
EUR/RUB
Cryptocurrency

SparkKitty Malware Turns Smartphone Galleries into Security Liabilities

A persistent mobile malware campaign known as SparkKitty is back in the spotlight, reminding users that storing cryptocurrency recovery phrases in phone photo galleries invites immediate theft. While recent warnings have renewed alarm, security researchers confirm the threat traces back to a 2025 discovery rather than a fresh emergence.

SparkKitty Malware Turns Smartphone Galleries into Security Liabilities

The SparkKitty campaign bypasses traditional security by targeting the most common storage habit among crypto users: taking screenshots of 12 or 24-word seed phrases. Once granted permission to access a device's photo library, the malware silently uploads images to attacker-controlled servers. While earlier iterations relied on optical character recognition to scan for specific text, newer samples simply exfiltrate entire collections of photos, potentially compromising identity documents and passwords alongside wallet keys.

Kaspersky first documented the operation in June 2025, noting that malicious code had infiltrated both the Apple App Store and Google Play through seemingly benign tools. On iOS, the malware often hides within modified software development frameworks, while Android versions frequently appear as messaging apps or crypto exchange tools. Although platforms like Google and Apple removed identified apps such as SOEX and 币coin, the danger persists through sideloaded packages and fake websites, particularly for users in Southeast Asia and China.

Security experts emphasize that digital backups of recovery phrases offer no protection against this level of access. If a seed phrase is stored as an image, its security is effectively nullified once the malware gains gallery permissions. The recommended response for anyone who suspects exposure is immediate: generate a new wallet on a secure, clean device and transfer all assets. Beyond migrating funds, users must audit app permissions, delete non-essential photo access, and switch to offline storage methods like paper or metal backups to ensure their private keys remain inaccessible to remote attackers.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!