SparkKitty is a cross-platform mobile infostealer targeting Android and iOS devices, with a strong focus on cryptocurrency theft. It is associated with campaigns that distribute trojanized mobile applications through both official app marketplaces and third-party channels, including fake or modified crypto, messaging, social-media, and gambling apps. The malware is linked by multiple researchers to the earlier SparkCat activity and is assessed to target users in China and Southeast Asia in particular, although exposure is not limited to those regions.
Its core behavior centers on obtaining access to a victim’s photo gallery and harvesting sensitive information stored in images. SparkKitty scans screenshots and other gallery content, and in many observed cases uses optical character recognition to extract wallet seed phrases, passwords, QR codes, and other sensitive text embedded in photos. Some variants reportedly exfiltrate all accessible images, while others selectively identify high-value content. Stolen data is then transmitted to attacker-controlled infrastructure together with device metadata, enabling follow-on cryptocurrency wallet compromise and broader account theft.
On Android, SparkKitty has been observed in Java and Kotlin variants, including malicious modules for rooted devices using Xposed or LSPosed to extend persistence and monitoring. On iOS, the malware has been embedded directly in apps or hidden inside obfuscated or masquerading frameworks and libraries to evade review and blend with legitimate application components. Delivery has included malicious apps published in official stores as well as sideloaded packages installed through social-engineering flows and fake App Store-style pages.
SparkKitty is notable for abusing ordinary mobile permissions and user trust rather than relying solely on overtly destructive behavior, which helps it remain less visible to victims while continuously collecting sensitive data. The malware is especially dangerous to users who store cryptocurrency recovery phrases as screenshots or photos, because compromise of those images can enable immediate theft of wallet assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was distributed through unofficial sources as well as Google Play and App Store... In both the Android and iOS versions, the malicious payload was part of the app itself, not of a third-party SDK or framework. | The threat actor distributed apps containing a malicious SDK/framework... On iOS, the malicious payload is delivered as frameworks (primarily mimicking AFNetworking.framework or Alamofire.framework) or obfuscated libraries disguised as libswiftDarwin.dylib, or it can be embedded directly into the app itself.
Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.
T1546.008 — Accessibility Features (Privilege Escalation) ; T1546.008 — Accessibility Features (Persistence)
application crypto nommée « coin » publiée sur l’ Apple App Store, dissimulant la charge malveillante dans des frameworks obfusqués
It retrieves the Base64-encoded value of the ccc key... decoded and then decrypted using AES-256 in ECB mode... The decrypted value is a list of URLs...
26 мошеннических приложений, маскировавшихся под MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken и Bitpie
the malware sends a GET request to the /api/getImageStatus endpoint, transmitting app details and the user’s UUID... the Trojan writes a hexadecimal number... an MD5 hash of a string containing the infected device’s IMEI, MAC address, and a random UUID.
On every launch, the app requested access to the user’s photo gallery... Next, the malware requests access to the user’s photo gallery.
The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.
the malware harvests credentials, personal data, and device information while minimizing signs of compromise
Вредоносное ПО отслеживало экраны создания и восстановления кошелька в поисках сид-фраз
After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.
It would then use an OCR model to select and exfiltrate images of interest... ML Kit searched for text blocks and then broke them down into lines. If at least three lines containing a word with a minimum of three letters were found, the Trojan would send the image to the attackers’ server.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparative wallet-theft case illustrating the risk of exposing recovery phrases to untrusted apps.
Mobile malware targeting Android devices that steals credentials, personal data, and device information while maintaining stealthy, persistent access. It is distributed through malicious apps and social-engineering tactics and is designed to minimize signs of compromise.
Cross-platform mobile infostealer targeting Android and iOS that scans images stored on the device using OCR to extract sensitive data such as cryptocurrency wallet seed phrases, passwords, and QR codes, then exfiltrates the data and device metadata to C2 infrastructure.
Malware associated with a campaign using fake crypto-wallet apps and trojanized wallet versions to steal wallet recovery data. It monitored wallet creation and restoration screens to capture seed phrases and recovery information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.