HomeNewsDecryptHow the ‘SparkKitty’ Trojan Is Stealing Crypto Wallet Data From Phones

How the ‘SparkKitty’ Trojan Is Stealing Crypto Wallet Data From Phones

-



In brief

  • The Trojan steals images from phones, likely to extract seed phrases.
  • It is distributed through App Store, Google Play, and third-party sites.
  • Kaspersky has linked it to the prior SparkCat spyware campaign.

A newly discovered Trojan dubbed “SparkKitty” is infecting smartphones and siphoning off sensitive data, potentially enabling attackers to drain victims’ cryptocurrency wallets, cybersecurity firm Kaspersky said in a report on Tuesday.

The malware is embedded in apps related to crypto trading, gambling, and even modified versions of TikTok.

Once installed via deceptive provisioning profiles—used for running iOS apps or modified apps—SparkKitty requests access to the photo gallery. It monitors for changes, creates a local database of stolen images, and uploads photos to a remote server.

“We suspect the attackers’ main goal is to find screenshots of crypto wallet seed phrases,” Kaspersky said.

Currently, the malware primarily targets victims in China and Southeast Asia. However, the firm warned that there was nothing to stop it from spreading to other regions.

In its 2024 report, TRM Labs estimated that nearly 70% of the $2.2 billion in stolen crypto last year resulted from infrastructure attacks, particularly those involving the theft of private keys and seed phrases. 

Infected devices

Malware like SparkKitty enables such thefts as attackers can use data from infected devices to search for wallet credentials. Seed phrases are highly valuable because they allow full access to a user’s crypto wallet.

SparkKitty is believed to be linked to the SparkCat spyware campaign first uncovered in January 2025, which similarly used malicious SDKs to gain access to photos on user devices. 

While SparkCat focused its spyware on images with seed phrases using Optical Character Recognition (OCR technology, SparkKitty indiscriminately uploads photos, presumably to be processed later.

Its presence has been confirmed in both Android and iOS apps on their respective app stores, including disguised as crypto-themed tools and TikTok mods. 

SparkKitty joins a host of other crypto-targeting malware and trojans that have gained popularity among hackers over the last few years.

Among them, the information stealer Noodlophile has been found embedded in AI tools available for download online, taking advantage of current interest around the technology.

Hackers build convincing-looking AI sites and then advertise them via social media to attract unsuspecting victims. 

An international law enforcement effort in May targeted key infrastructure related to the distribution of another strain of malware, LummaC2, which has been linked to over 1.7 million theft attempts. 

LummaC2 aimed to steal information related to login credentials, including for crypto wallets. 

Edited by Sebastian Sinclair

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

News source: How the ‘SparkKitty’ Trojan Is Stealing Crypto Wallet Data From Phones
Read the full article and more directly from the source!

Enjoying our initiative? Support us with a BTC donation:
BTC Wallet: bc1q0faa2d4j9ezn29uuf7c57znsm5ueqwwfqw9gde

LATEST POSTS

The Value-For-Value Future Of Money And Work

When someone holds your funds, these days everyone recognizes the inherent risk: The custodian might misuse the money or fail to safeguard...

Actions Speak Louder Than Words

Let’s look at two things that Bitcoin Knots users claim to be proponents of and champions for in their crusade against Bitcoin...

B HODL Joins The Bitcoin Treasury Race With 100 Bitcoin Buy

The UK’s newest Bitcoin-focused public company wasted no time putting capital to work. Fresh off its debut on the Aquis Stock Exchange,...

Bitcoin Could Hit $1M If Banks Don’t Interfere

Coinbase CEO Brian Armstrong believes Bitcoin could reach $1 million per coin by the end of this decade — but only if policymakers hold...

Most Popular

spot_img