Threat Profile: SparkKitty Malware
Published 7/27/2026, 6:02:27 PM
SparkKitty is a critical cross-platform threat specifically designed to automate the theft of cryptocurrency seed phrases from mobile devices. First identified in mid-2025 but active since February 2024, the malware is highly serious because it successfully bypassed the security vetting of both the Apple App Store and Google Play Store [Source: https://securelist.com/sparkkitty-ios-android-malware/116793/].
The malware's primary innovation is its use of Optical Character Recognition (OCR) to scan a user's entire photo gallery for screenshots or photos of recovery phrases, making it a direct threat to any user who has digitally backed up their keys as an image [Source: https://www.kaspersky.com/blog/ios-android-stealer-sparkkitty/53675/].
Threat Profile: SparkKitty Malware
| Metric | Details |
|---|---|
| Target Platforms | iOS and Android |
| Primary Mechanism | OCR-based image scanning for mnemonic phrases |
| Known Malicious Apps | 币coin (iOS), SOEX (Android) |
| Infection Scale | 10,000+ downloads for SOEX alone [Source: https://kaspersky.com/blog/ios-android-stealer-sparkkitty/53675/] |
| Persistence Level | High (uses Xposed modules on Android; Enterprise Profiles on iOS) |
| Severity | Critical |
Technical Mechanism of Compromise
SparkKitty operates by gaining access to the device's photo library. Once granted permission—often under the guise of a legitimate crypto-tracking or social app—it executes the following:
- Image Exfiltration: The malware scans existing and new photos. Some variants exfiltrate the entire gallery to a Command & Control (C2) server, while others perform local analysis [Source: https://www.broadcom.com/support/security-center/protection-bulletin/new-mobile-crypto-stealing-malware-sparkkitty].
- OCR Processing: It uses text-extraction engines (reportedly Google ML Kit-based) to identify strings of words that match the BIP-39 mnemonic wordlist [Source: https://www.broadcom.com/support/security-center/protection-bulletin/new-mobile-crypto-stealing-malware-sparkkitty].
[Note: specific mnemonic validation algorithm details not independently confirmed] - Obfuscation: On iOS, the malicious code is hidden within frameworks that mimic legitimate libraries like
AFNetworkingorAlamofireto evade detection by automated store scanners [Source: https://cyberint.com/blog/dark-web/sparkkitty-malware-an-emerging-threat-to-mobile-users/].
Scope and Scale
The threat is global, though it has specifically targeted users of Chinese-language crypto tools and social media clones.
- Affected Apps: The iOS app 币coin and the Android app SOEX were confirmed as primary vectors. SOEX reached over 10,000 downloads on Google Play before being removed [Source: https://kaspersky.com/blog/ios-android-stealer-sparkkitty/53675/].
- Targeted Data: While the malware focuses on seed phrases, it also targets private keys and general sensitive documents stored as images [Source: https://www.darkreading.com/mobile-security/sparkkitty-swipes-pics-ios-android-devices].
- Missing Data: The total aggregate number of victims across all third-party stores and the specific blockchains targeted for automated draining remain unconfirmed in current research.
Severity Assessment
The risk is extreme for mobile users who store seed phrases in their "Photos" or "Screenshots" folders. Because the malware can operate in the background and exfiltrate data to remote servers, a compromise can occur months before a user notices their funds have been moved.
Security researchers recommend that any user who has installed the "币coin" or "SOEX" apps immediately migrate their assets to a new wallet address generated on a clean device, as the original seed phrase must be considered compromised [Source: https://securelist.com/sparkkitty-ios-android-malware/116793/].
In summary, SparkKitty is a sophisticated, active threat that exploits the common but insecure habit of taking screenshots of seed phrases. Its ability to infiltrate official app stores makes it significantly more dangerous than typical "sideloaded" malware.