Loading prices…
🩸BEARISH

Cross-Platform SparkKitty Trojan Uses Photo OCR to Drain Crypto

Cross-platform spyware hiding in official app stores used OCR to lift wallet seed phrases straight out of users' camera rolls, with one Android app clearing 10K downloads before removal.

Check Point researchers detailed SparkKitty, a cross-platform malware family targeting Android and iOS devices, that uses optical character recognition to scan a victim's photo library for screenshots containing cryptocurrency wallet seed phrases.

The malware reached users through both official app stores and third-party channels, including an Android app that surpassed 10,000 downloads before it was taken down. Distribution vectors in the official stores suggest the operators got past review, not just sideloaded onto victim devices.

Why it matters

Seed phrases written down or screenshotted for safekeeping are a single point of failure, and SparkKitty weaponizes that habit at scale. OCR-based photo scanning turns every wallet backup image into an exfiltration target, and the malware's cross-platform reach means iOS users are not protected by Apple's walled garden alone. Distribution through official stores, rather than purely third-party APK sites, raises the bar for the kind of vigilance users need to apply before installing any wallet-adjacent app.

Market impact

Wallet vendors and security teams will need to revisit guidance that has long told users to physically write seed phrases on paper, advice that exists precisely because digital copies are attack surface. The disclosure adds pressure on mobile OS vendors to tighten review pipelines for apps requesting broad photo-library access, and on wallet developers to discourage screenshot-based backups inside their own apps.

Frequently asked questions

  1. What is SparkKitty malware?

    SparkKitty is a cross-platform malware family disclosed by Check Point that targets Android and iOS devices. It uses optical character recognition to scan a victim's photo library for screenshots containing cryptocurrency wallet seed phrases.

  2. How was SparkKitty distributed?

    The malware reached users through both official app stores and third-party channels. One Android app surpassed 10,000 downloads before being removed, indicating the operators cleared app-store review rather than relying solely on sideloading.

  3. Can iOS users be infected by SparkKitty?

    Yes. Check Point's research found SparkKitty targeting both Android and iOS, meaning Apple's walled garden does not by itself protect against apps that pass review and later request broad photo-library access.

  4. Why are seed phrase screenshots dangerous?

    A seed phrase is the master key to a crypto wallet. Anyone who obtains it can drain the wallet. Screenshots stored in a phone's photo library turn that single point of failure into a target for malware that scans images, which is exactly what SparkKitty does.

  5. What should crypto users do after this disclosure?

    Users should avoid storing seed phrases as screenshots, write them on paper or use hardware wallets, and audit which installed apps have access to their photo library. Wallet vendors are also likely to revisit guidance that has long warned against digital seed-phrase backups.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →