-
SparkKitty malware disguised as messaging and crypto apps bypassed security checks on the Apple App Store and Google Play to access device photo galleries.
-
The malicious software used Optical Character Recognition technology to scan saved screenshots for cryptocurrency wallet seed phrases, it also transmitted the stolen files to remote servers.
-
Experts in cybersecurity advise mobile users to delete recovery phrase photos, revoke gallery permissions for non-essential apps, and store seed phrases offline.

Researchers in cybersecurity have revealed a sophisticated type of malware already operating in important mobile platform stores. The data-stealing malware called SparkKitty managed to evade the security systems of both Google Play and App Store.
The hijacked malware was made to look and operate like virtual currency apps, financial calculators, and mobile messaging apps. When installed on users’ gadgets, the trojan silently seeks permission to access the media files. The malware then systematically scanned saved photos to locate private recovery phrases for digital currency wallets.
Security analysts at Check Point and partner intelligence teams tracked the malicious campaign across multiple global regions. One infected application distributed through Google Play accumulated more than 10,000 downloads, this was before store administrators removed the file.
The incident highlights growing security vulnerabilities within official software distribution channels. Cybercriminals increasingly target smartphone image libraries to steal sensitive financial records and account passcodes. Mobile device users must remain cautious when granting media storage permissions to newly installed applications.
How SparkKitty Exploits Photo Gallery Permissions
The technical architecture behind SparkKitty relies on automated image analysis algorithms to extract hidden text data. When users open an infected application for the first time, the software displays a standard system prompt.
The prompt indicates that users should allow unrestricted access to their photo albums under the pretext of setting profile pictures or uploading documents. Most mobile phone users allow this access without being aware of the related security issues.
After receiving permission, SparkKitty deploys Optical Character Recognition libraries directly on the device. The embedded code reads stored images, screenshots, and saved photo files in the background.
The scanning tool specifically searches for unique twelve-word or twenty-four-word seed phrases. Consequently, the software isolates photos containing written recovery keys and extracts readable text fragments.
The malware sets up concealed network links to relay information between the infected device and the distant command and control servers. Moreover, it sends the stolen photo files and the text strings from the user to the adversaries.
This implies that the cybercriminals can obtain access to the private cryptocurrency wallet data of the owner without their antivirus software finding out about it.
Major Risks to Mobile Cryptocurrency Wallet Owners
Cryptocurrency storage systems depend on secret recovery phrases to verify the ownership of accounts and restore wallet access. Many investors write down seed phrases on physical paper, but others take digital screenshots for quick reference.
Storing unencrypted images of seed phrases on smartphones creates extreme financial exposure. Other crypto-stealing methods target wallet addresses directly. Recently, a fake Google Notes extension was found swapping wallet addresses to steal cryptocurrency. Cybercriminals who obtain these recovery words can import the wallet into their own devices immediately.
Once attackers restore a compromised wallet, they execute automated draining scripts to transfer funds instantly. Blockchain transactions remain permanent and irreversible across decentralized networks.
However, victims rarely discover the theft until after criminals empty their token accounts completely. Victims cannot request chargebacks or reverse fraudulent transfers through traditional banking customer service channels.
Therefore, mobile users must recognize that saving financial credentials in camera rolls compromises overall wallet security. Security experts stress that digital screenshots remain a prime target for mobile spyware creators worldwide.
Mobile Ecosystem Safeguards and User Protection Steps
App store operators continuously update automated screening tools to spot malicious code frameworks before publication. Both Apple and Google removed identified SparkKitty applications as soon as security researchers reported the threats.
Platform teams revoked developer certificates associated with the malicious software accounts. Besides, mobile operating systems now offer granular media permission options that restrict applications to selected photos rather than full gallery access.
Smartphone owners must review active application permissions within their device settings menus regularly. Users should revoke photo storage access for non-essential applications like casual games or basic utility tools.
In addition, security specialists recommend deleting all screenshots containing seed phrases, banking details, or passwords from cloud backups. Individuals holding digital assets should record recovery words on physical paper or store them inside hardware security modules.
Keeping sensitive credentials off connected mobile devices prevents photo-scanning malware from accessing private financial assets.