Check Point specialists have identified malware that steals seed phrases from mobile device image galleries

7/27/2026, 01:59 PMЕвгения Слив

Cybersecurity experts at Check Point Research have discovered the SparkKitty malware, designed to steal the seed phrases of cryptocurrency wallets from image galleries on devices running the iOS and Android operating systems. Unlike traditional methods of data interception, such as keylogging or clipboard monitoring, this malicious software uses optical character recognition (OCR) technology to analyze photos and screenshots for confidential information. After gaining access to the gallery, the program scans images, extracts text data and transmits it to remote servers controlled by intruders, which allows bypassing standard protection mechanisms for mobile devices.

This threat was first identified by Kaspersky experts in early 2024 under the name SparkCat, but subsequently the malware underwent significant changes. SparkKitty is distributed through official app stores, where attackers host software under the guise of legitimate cryptocurrency services, messengers, and entertainment applications. For the iOS platform, the malicious code was integrated into the 币coin cryptocurrency application hosted on the App Store, while the program used the obfuscated AFNetworking and libswiftDarwin dylib frameworks to conceal malicious activity and bypass moderation. The Android version was distributed through the SOEX app, which was downloaded more than 10,000 times and masqueraded as a messaging and cryptocurrency platform.

Gaining access to the seed phrase provides attackers with full control over the user's cryptocurrency wallet and the ability to withdraw funds as soon as possible. The malware operates in the background, which makes it difficult for the owner to detect a compromise of the device in a timely manner. This situation highlights the urgency of the problem of mobile device security in the context of storing cryptocurrency assets. Earlier, experts from SlowMist also recorded new attack methods aimed at intercepting Telegram Desktop sessions bypassing two-factor authentication, which indicates the systematic nature of threats to users of cryptocurrency services.

Popular news