Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
A New Malware on iPhone and Android Can Quietly Steal Your Crypto

A New Malware on iPhone and Android Can Quietly Steal Your Crypto

BeInCrypto2025/06/24 14:07
By: Landon Manning
SparkKitty, a dangerous malware targeting mobile crypto wallets, secretly scans photos for seed phrases. Kaspersky warns users to protect sensitive data and avoid risky apps.

SparkKitty, a dangerous new malware, is targeting mobile devices to compromise crypto wallets. It searches through users’ image data to uncover and steal seed phrases.

In recent cases, the malware infected phones through compromised apps, with several bait programs catering to lure crypto users. Thankfully, app store moderation has removed many of SparkKitty’s attack vectors.

How SparkKitty Targets Crypto Wallet Apps

Popular security firm Kaspersky identified this new malware today after months of observation across different mobile operating systems.

Earlier in February, the firm discovered SparkCat, an earlier iteration of this malware. After the previous discovery, the malicious developers repackaged this trojan through new apps.

Our researchers uncovered #SparkKitty, a stealthy Trojan targeting both #iOS and #Android devices.It captures images and device data from infected phones and transmits them to the attackers. The Trojan was embedded in apps related to #crypto, gambling, and even a trojanized… pic.twitter.com/2CjjSwcpeo

— Kaspersky (@kaspersky) June 24, 2025

According to the company’s full report, this piece of malware is specifically focused on targeting crypto users, especially in China and Southeast Asia.

Hackers embedded SparkKitty into crypto-related apps, like price trackers and messengers with crypto-buying functionality. One such compromised messenger, SOEX, was downloaded over 10,000 times before removal.

SparkKitty’s operators also branched out to include casino apps, adult sites, and fake TikTok clones. Even if a user downloaded a contaminated app, the malware wouldn’t automatically start looking for crypto.

Instead, the app would ostensibly function normally, asking for access to users’ photos. It would continue appearing normal even after gaining this permission.

In other words, this malware would repeatedly scan image data for signs of a crypto seed phrase, double-checking the compromised device periodically.

Kaspersky’s researchers have several reasons to believe that SparkKitty is an upgraded SparkCat. For example, they share several debug symbols, code construction, and even a few compromised vector apps.

However, SparkKitty is more ambitious than SparkCat. The earlier malware would focus on penetrating crypto security, while the upgraded version can compromise many types of sensitive data.

A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 0 SlowMist TI Alert A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 1A new malware named #SparkKitty that steals all photos from infected iOS & Android devices — searching for crypto wallet seed phrases.A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 2 Delivered via:A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 3 "币coin" (App Store)A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 4 "SOEX" (Google Play, 10K+ installs, now removed)A New Malware on iPhone and Android Can Quietly Steal Your Crypto image 5 Casino apps, adult… pic.twitter.com/47WDc8l6tQ

— SlowMist (@SlowMist_Team) June 24, 2025

Nonetheless, SparkKitty’s main priority is still in uncovering seed phrases.

Overall, the best caution for users is never to store seed phrases digitally. Don’t even take a photo of it.

There’s no shortage of recent scams and malware that can compromise this password, thereby allowing attackers to steal all your crypto. It’s important not to give sketchy apps access to your devices, but it’s doubly vital to protect your seed phrase.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Three Key Signals Crypto Investors Must Watch Amid the Fed’s Rate Decision Turmoil

The Federal Reserve’s September interest rate meeting is drawing attention due to personnel changes, shifting the focus from economic data to an assessment of institutional resilience. The market anticipates two possible rate cut paths: a 25 basis point cut would boost global assets, while a 50 basis point cut might trigger panic. The outcome of the meeting will impact the Federal Reserve’s credibility and the crypto market. Summary generated by Mars AI This summary was generated by the Mars AI model and its accuracy and completeness are still being iteratively improved.

MarsBit2025/09/16 03:18

Trending news

More
1
Native Markets Becomes Issuer of Hyperliquid’s Stablecoin USDH
2
Three Key Signals Crypto Investors Must Watch Amid the Fed’s Rate Decision Turmoil

Crypto prices

More
Bitcoin
Bitcoin
BTC
$115,155.7
-0.34%
Ethereum
Ethereum
ETH
$4,518.39
-2.47%
XRP
XRP
XRP
$2.98
-2.10%
Tether USDt
Tether USDt
USDT
$1
-0.02%
BNB
BNB
BNB
$919.77
-1.40%
Solana
Solana
SOL
$234.8
-3.28%
USDC
USDC
USDC
$0.9999
-0.01%
Dogecoin
Dogecoin
DOGE
$0.2668
-4.72%
TRON
TRON
TRX
$0.3454
-1.50%
Cardano
Cardano
ADA
$0.8596
-3.83%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter