SparkKitty is a cross-platform mobile infostealer targeting Android and iOS devices, with a strong focus on cryptocurrency theft. It is associated with campaigns that distribute trojanized mobile applications through both official app marketplaces and third-party channels, including fake or modified crypto, messaging, social-media, and gambling apps. On iOS, related delivery chains have also used App Store-themed phishing pages and enterprise or developer provisioning profiles to sideload malicious applications outside normal store controls. Activity has been linked by multiple researchers to the SparkCat cluster, and SparkKitty is widely assessed as a related or evolved mobile stealer family.
Its core behavior centers on obtaining access to the victim’s photo gallery and harvesting sensitive information stored in images, especially cryptocurrency wallet recovery phrases saved as screenshots. Observed variants scan existing and newly created images, and some use optical character recognition to extract seed phrases, passwords, QR-code content, and other text from photos. Other reporting indicates some variants exfiltrate images more broadly rather than only selected OCR matches. Stolen data is then transmitted to attacker-controlled infrastructure together with device metadata.
SparkKitty has been observed embedded directly in malicious apps and hidden inside obfuscated mobile frameworks or libraries to reduce scrutiny and hinder analysis. On Android, reported variants include conventional app-based samples as well as rooted-device modules using Xposed or LSPosed for extended persistence. The malware is designed to operate quietly, blending into normal mobile activity while maintaining ongoing access to gallery content and monitoring for newly added images.
Victims are primarily cryptocurrency users, particularly those who store wallet seed phrases or other recovery material as screenshots or photos. Reported targeting has been concentrated in China and Southeast Asia, though exposure is not inherently limited to those regions. SparkKitty has also been discussed in connection with broader fake-wallet and wallet-impersonation ecosystems that use phishing, sideloading, and trojanized wallet apps to steal crypto assets and credentials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was distributed through unofficial sources as well as Google Play and App Store... In both the Android and iOS versions, the malicious payload was part of the app itself, not of a third-party SDK or framework. | The threat actor distributed apps containing a malicious SDK/framework... On iOS, the malicious payload is delivered as frameworks (primarily mimicking AFNetworking.framework or Alamofire.framework) or obfuscated libraries disguised as libswiftDarwin.dylib, or it can be embedded directly into the app itself.
Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.
T1546.008 — Accessibility Features (Privilege Escalation) ; T1546.008 — Accessibility Features (Persistence)
application crypto nommée « coin » publiée sur l’ Apple App Store, dissimulant la charge malveillante dans des frameworks obfusqués
It retrieves the Base64-encoded value of the ccc key... decoded and then decrypted using AES-256 in ECB mode... The decrypted value is a list of URLs...
26 мошеннических приложений, маскировавшихся под MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken и Bitpie
the malware sends a GET request to the /api/getImageStatus endpoint, transmitting app details and the user’s UUID... the Trojan writes a hexadecimal number... an MD5 hash of a string containing the infected device’s IMEI, MAC address, and a random UUID.
On every launch, the app requested access to the user’s photo gallery... Next, the malware requests access to the user’s photo gallery.
The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.
the malware harvests credentials, personal data, and device information while minimizing signs of compromise
Вредоносное ПО отслеживало экраны создания и восстановления кошелька в поисках сид-фраз
After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.
It would then use an OCR model to select and exfiltrate images of interest... ML Kit searched for text blocks and then broke them down into lines. If at least three lines containing a word with a minimum of three letters were found, the Trojan would send the image to the attackers’ server.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile malware targeting Android devices that steals credentials, personal data, and device information while maintaining stealthy, persistent access. It is distributed through malicious apps and social-engineering tactics and is designed to minimize signs of compromise.
Cross-platform mobile infostealer targeting Android and iOS that scans images stored on the device using OCR to extract sensitive data such as cryptocurrency wallet seed phrases, passwords, and QR codes, then exfiltrates the data and device metadata to C2 infrastructure.
Malware associated with a campaign using fake crypto-wallet apps and trojanized wallet versions to steal wallet recovery data. It monitored wallet creation and restoration screens to capture seed phrases and recovery information.
Mobile stealer targeting cryptocurrency users on iOS and Android. It requests photo/gallery access, uses OCR to extract seed phrases and other sensitive text from screenshots and images, collects device metadata, and exfiltrates the results to attacker-controlled servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.