In brief
- SparkKitty scanned users’ photo libraries for crypto wallet seed phrases and other sensitive information.
- The malware was distributed through malicious apps on Apple’s App Store, Google Play, and third-party app stores.
- Researchers warn that storing wallet recovery phrases as screenshots can expose crypto assets to theft.
A new report from cybersecurity firm Check Point details how the SparkKitty malware campaign targeted cryptocurrency users by scanning photos stored on infected Android and iPhone devices for wallet recovery phrases and other sensitive information.
First discovered by Kaspersky in June 2025, Check Point’s analysis detailed how the malware spread through Apple’s App Store, Google Play, and third-party app…







