A new malware, dubbed SparkKitty, has been identified by cybersecurity firm Kaspersky. This malicious software targets both iOS and Android devices, primarily through seemingly legitimate apps on major app stores. SparkKitty's main objective is to steal images from infected devices, specifically looking for screenshots of cryptocurrency seed phrases, posing a significant threat to digital asset holders.
Key Takeaways
-
SparkKitty is a new malware designed to steal images, particularly crypto seed phrase screenshots, from mobile devices.
-
It targets both iOS and Android users through compromised apps found on official app stores.
-
The malware indiscriminately steals all images from a device's photo gallery.
-
Two crypto-themed apps, 币coin and SOEX, were identified as vectors for SparkKitty.
-
Google has removed the SOEX app and banned its developer from Google Play.
-
SparkKitty is believed to be related to the previously discovered SparkCat malware.
-
The primary targets are users in Southeast Asia and China, though it can affect users globally.
SparkKitty's Modus Operandi
SparkKitty operates by infiltrating mobile devices through seemingly innocuous applications available on platforms like the Apple App Store and Google Play. Once installed, the malware gains access to the device's photo gallery and proceeds to steal all images. While its primary focus is to identify and exfiltrate screenshots containing cryptocurrency seed phrases, it can also compromise other sensitive data present in the stolen images.
Distribution Channels and Targets
Kaspersky analysts Sergey Puzan and Dmitry Kalinin reported that SparkKitty has been distributed through various types of applications. Notably, two crypto-themed apps were identified: 币coin, marketed as a crypto information tracker on the App Store, and SOEX, a messaging app with "crypto exchange features" on Google Play. The SOEX app had been installed over 10,000 times before Google removed it and banned the developer. Beyond crypto apps, SparkKitty has also been found in casino apps, adult-themed games, and malicious TikTok clones.
The malware campaign primarily targets users in Southeast Asia and China, as indicated by the nature of the infected apps. However, experts warn that SparkKitty has no technical limitations preventing it from affecting users in any other region worldwide.
Connection to SparkCat
SparkKitty shares significant similarities with SparkCat, another malware discovered by Kaspersky earlier this year. Both variants are designed to scan user photos for crypto wallet recovery phrases. Puzan and Kalinin suggest that both versions likely originate from the same source, given their shared features and similar file paths found in the attackers' systems. While not technically complex, this ongoing campaign, active since at least early 2024, poses a substantial threat to users, as SparkKitty is less selective about the photos it steals compared to its predecessor.
Sources
-
Malware Steals Photos To Find Crypto Seed Phrases, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.