Overview
- Kaspersky first published a technical report on SparkKitty on June 23, 2025, and July 27, 2026 coverage renewed public warnings rather than reporting a newly discovered variant.
- The malware uses optical character recognition to read images in a phone’s photo gallery, looks for 12‑ or 24‑word wallet recovery phrases stored as screenshots, and uploads matched images to attacker servers.
- Kaspersky and other researchers found infected apps on the Apple App Store (the app 币coin) and Google Play (SOEX) before the listings were removed, and variants continue to circulate through sideloaded APKs, modified social apps, enterprise provisioning, and third‑party stores.
- There is no public, confirmed evidence of mass wallet drains or a quantified victim or loss total, so researchers urge immediate steps such as deleting seed screenshots, revoking photo permissions, creating a new wallet on a clean device, and moving funds from any exposed wallet.
- Linked to an earlier SparkCat campaign and active since at least February 2024, the operation primarily targeted users in China and Southeast Asia and highlights persistent user operational‑security gaps such as saving seeds as images and granting broad photo access.