Crypto Malware Alert: ‘SparkCat’ Infects Android and iOS Apps, Steals Wallet Recovery Phrases

Cybersecurity researchers at Kaspersky Labs have uncovered a dangerous new malware called ‘SparkCat’, hidden inside Android and iOS app development kits (SDKs). This malicious software is designed to scan images on infected devices, searching for crypto wallet recovery phrases, passwords, and private messages—allowing hackers to steal funds without even needing login credentials.

How Does SparkCat Work?

SparkCat is particularly dangerous because it targets sensitive information stored in images rather than traditional phishing attacks or password theft. It operates by:

🔹 Using Google’s ML Kit OCR technology to extract text from screenshots and images.
🔹 Scanning devices for recovery phrases and sensitive data stored in pictures.
🔹 Sending stolen information to attackers, giving them full access to crypto wallets.

The malware is embedded within legitimate and fake apps available on Google Play Store and Apple App Store, disguised as analytics modules.

Who’s Affected?

So far, around 242,000 devices have been infected, with most cases reported in Europe and Asia. The malware’s origin remains unclear, but code analysis suggests the developer is fluent in Chinese.

How Did It Spread?

Experts suspect the malware’s spread could be due to:

A supply chain attack—where hackers compromised trusted app-making tools.
Intentional embedding—where developers knowingly included the malware in apps.

What Should You Do?

With SparkCat actively stealing sensitive data, users are urged to take immediate action:

Avoid storing crypto recovery phrases, passwords, or private data in images.
Uninstall suspicious apps, especially ones requesting unnecessary permissions.
Be cautious when granting apps access to your photo gallery.
Regularly update your security software and perform device scans.

What’s Next?

Google and Apple have yet to respond to the findings, but security experts warn that this could be just the beginning of more sophisticated crypto-targeted malware. As crypto adoption grows, so do cyber threats—staying informed and practicing digital security is more important than ever.

Have you checked your phone for suspicious apps lately? Stay safe and protect your crypto!

bitcoin
Bitcoin (BTC) $ 83,435.35
ethereum
Ethereum (ETH) $ 1,907.94
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.34
bnb
BNB (BNB) $ 628.19
solana
Solana (SOL) $ 127.97
usd-coin
USDC (USDC) $ 1.00
cardano
Cardano (ADA) $ 0.722347
dogecoin
Dogecoin (DOGE) $ 0.171794
tron
TRON (TRX) $ 0.216403
staked-ether
Lido Staked Ether (STETH) $ 1,904.38
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 83,294.32
pi-network
Pi Network (PI) $ 1.36
leo-token
LEO Token (LEO) $ 9.78
chainlink
Chainlink (LINK) $ 13.72
the-open-network
Toncoin (TON) $ 3.42
stellar
Stellar (XLM) $ 0.273136
usds
USDS (USDS) $ 1.00
wrapped-steth
Wrapped stETH (WSTETH) $ 2,285.03
hedera-hashgraph
Hedera (HBAR) $ 0.192141
avalanche-2
Avalanche (AVAX) $ 18.51
shiba-inu
Shiba Inu (SHIB) $ 0.000013
sui
Sui (SUI) $ 2.29
litecoin
Litecoin (LTC) $ 93.21
mantra-dao
MANTRA (OM) $ 6.84
bitcoin-cash
Bitcoin Cash (BCH) $ 336.93
polkadot
Polkadot (DOT) $ 4.36
ethena-usde
Ethena USDe (USDE) $ 0.999972
bitget-token
Bitget Token (BGB) $ 4.43
weth
WETH (WETH) $ 1,907.82
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
hyperliquid
Hyperliquid (HYPE) $ 13.70
whitebit
WhiteBIT Coin (WBT) $ 28.52
wrapped-eeth
Wrapped eETH (WEETH) $ 2,026.38
monero
Monero (XMR) $ 211.52
uniswap
Uniswap (UNI) $ 6.19
susds
sUSDS (SUSDS) $ 1.04
aptos
Aptos (APT) $ 5.38
dai
Dai (DAI) $ 0.999952
near
NEAR Protocol (NEAR) $ 2.55
pepe
Pepe (PEPE) $ 0.000007
okb
OKB (OKB) $ 48.74
mantle
Mantle (MNT) $ 0.840593
internet-computer
Internet Computer (ICP) $ 5.74
ondo-finance
Ondo (ONDO) $ 0.854723
gatechain-token
Gate (GT) $ 21.76
ethereum-classic
Ethereum Classic (ETC) $ 17.83
aave
Aave (AAVE) $ 170.12
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 83,457.36
crypto-com-chain
Cronos (CRO) $ 0.087846