Researchers uncovered SparkCat, a cross-platform malware campaign that embedded malicious Android SDKs and iOS frameworks into apps distributed through both official and unofficial marketplaces, including Google Play and Apple’s App Store. The malware used Google ML Kit OCR to scan victims’ photo galleries for cryptocurrency wallet recovery phrases, then selectively exfiltrated matching images to attacker-controlled infrastructure. Infected Android apps on Google Play were downloaded more than 242,000 times, and researchers described the iOS findings as the first known case of a stealer discovered in Apple’s App Store.
SparkCat appears to have been active since at least March 2024 and targeted users across Europe and Asia using multilingual keyword lists and localized dictionaries to identify seed phrases. The campaign also used obfuscation and a Rust-based custom C2 protocol to hinder analysis and manage communications. Following disclosure, Apple removed the malicious iOS apps on 2025-02-06, and Google removed the malicious Android apps on 2025-02-07.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Google removed the malicious Android applications associated with SparkCat from Google Play. The infected apps identified in Google Play had accumulated more than 242,000 downloads.
Apple removed the malicious iOS applications linked to SparkCat from the App Store. Researchers described the operation as the first known case of a stealer discovered in Apple’s App Store.
Researchers said the SparkCat malware campaign appears to have been active since at least March 2024. The campaign embedded malicious Android SDKs and iOS frameworks into apps distributed through official and unofficial app stores.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.