SparkKitty malware infiltrates App Store and Google Play to steal crypto seed phrases from photos

1 hour ago 2



Here’s a nightmare scenario most crypto holders haven’t considered: that screenshot of your seed phrase you took “just in case” is exactly what a new strain of malware is hunting for. Kaspersky researchers on June 23 published findings on SparkKitty, a mobile spyware Trojan that has been quietly embedded inside apps distributed through both the Apple App Store and Google Play. The malware rifles through users’ photo galleries, applies optical character recognition technology to identify screenshots containing crypto wallet seed phrases, and uploads them to attacker-controlled servers. How SparkKitty works The Trojan uses OCR, the same technology that lets your phone scan documents, to read text within images. It specifically hunts for patterns that match seed phrase formats. Once it finds a match, the image gets exfiltrated to servers controlled by the attackers, who can then reconstruct the wallet and drain its contents. On iOS, the malware disguised itself using fake frameworks designed to mimic legitimate networking libraries like AFNetworking and Alamofire. On Android, it leveraged malicious enterprise provisioning profiles to sideload itself onto devices. According to Kaspersk...

Read Entire Article