SparkKitty is a cross-platform mobile infostealer and spyware family targeting Android and iOS devices, with a primary focus on cryptocurrency users. It obtains access to device photo libraries and collects gallery images, screenshots, and associated device metadata. Variants use optical character recognition to identify and extract wallet recovery phrases, passwords, QR-code data, and other sensitive text stored in images, then exfiltrate the collected material to attacker-controlled infrastructure. The malware can monitor image directories for newly created content, extending exposure beyond files present at initial infection.
SparkKitty has been distributed in trojanized cryptocurrency, messaging, entertainment, gambling, and modified social-media applications through official mobile app stores, third-party stores, and sideloading chains that use deceptive landing pages. iOS variants have used obfuscated or maliciously modified application components, while Android variants include Java and Kotlin implementations; some Android infections on rooted devices use framework modules to maintain persistence. The campaign has been active since at least February 2024 and has particularly targeted users in Southeast Asia and China. SparkKitty is assessed to be related to the earlier SparkCat spyware campaign based on shared components and overlapping compromised applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was distributed through unofficial sources as well as Google Play and App Store... In both the Android and iOS versions, the malicious payload was part of the app itself, not of a third-party SDK or framework. | The threat actor distributed apps containing a malicious SDK/framework... On iOS, the malicious payload is delivered as frameworks (primarily mimicking AFNetworking.framework or Alamofire.framework) or obfuscated libraries disguised as libswiftDarwin.dylib, or it can be embedded directly into the app itself.
Delivery relies on two main paths: official store listings and sideloaded packages. Store versions raise trust and reach large audiences quickly, while sideloaded APKs and rooted-device modules extend persistence on Android through frameworks such as Xposed.
T1546.008 — Accessibility Features (Privilege Escalation) ; T1546.008 — Accessibility Features (Persistence)
application crypto nommée « coin » publiée sur l’ Apple App Store, dissimulant la charge malveillante dans des frameworks obfusqués
It retrieves the Base64-encoded value of the ccc key... decoded and then decrypted using AES-256 in ECB mode... The decrypted value is a list of URLs...
26 мошеннических приложений, маскировавшихся под MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken и Bitpie
the malware sends a GET request to the /api/getImageStatus endpoint, transmitting app details and the user’s UUID... the Trojan writes a hexadecimal number... an MD5 hash of a string containing the infected device’s IMEI, MAC address, and a random UUID.
On every launch, the app requested access to the user’s photo gallery... Next, the malware requests access to the user’s photo gallery.
The malware runs quietly in the background after users grant gallery permission, and it also collects device details that help attackers refine later campaigns.
the malware harvests credentials, personal data, and device information while minimizing signs of compromise
Many [malicious apps are] distributing the SparkKitty spyware, enabling data theft from compromised devices.
After permission is granted, it watches the image folder and periodically runs OCR libraries against new and existing files.
It would then use an OCR model to select and exfiltrate images of interest... ML Kit searched for text blocks and then broke them down into lines. If at least three lines containing a word with a minimum of three letters were found, the Trojan would send the image to the attackers’ server.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparative wallet-theft case illustrating the risk of exposing recovery phrases to untrusted apps.
Mobile malware targeting Android devices that steals credentials, personal data, and device information while maintaining stealthy, persistent access. It is distributed through malicious apps and social-engineering tactics and is designed to minimize signs of compromise.
Cross-platform mobile infostealer targeting Android and iOS that scans images stored on the device using OCR to extract sensitive data such as cryptocurrency wallet seed phrases, passwords, and QR codes, then exfiltrates the data and device metadata to C2 infrastructure.
Malware associated with a campaign using fake crypto-wallet apps and trojanized wallet versions to steal wallet recovery data. It monitored wallet creation and restoration screens to capture seed phrases and recovery information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.