Cybersecurity researchers have uncovered a sophisticated new spyware campaign dubbed SparkKitty that has successfully infiltrated both Apple and Google’s Play Store, marking a significant escalation in the spread of malware through official channels. The trojan-like software is the latest evolution in cryptocurrency-focused attacks, building on the previously detected SparkCatbut expanding its reach to both major mobile platforms.
See also: App Store: What Apple has done to strengthen security

The malware demonstrates impressive flexibility in its distribution methods, spreading not only through official app stores, but also through unofficial sources and modified apps. SparkKitty simultaneously targets iOS and Android devices, using techniques specifically tailored to each platform, aiming to bypass security mechanisms and gain permanent access to victims' devices.
The campaign has been ongoing since at least February 2024, suggesting a coordinated and long-term effort by cybercriminals to compromise mobile devices globally.
Securelist researchers observed that SparkKitty uses multiple distribution methods, aiming to maximize the chances of infection.
On iOS devices, the malicious payload is delivered via frameworks that mimic legitimate networking libraries, such as AFNetworking.framework or Alamofire.framework, while also using obfuscated libraries that are presented as supposedly system files, such as libswiftDarwin.dylib. The variant operates via Java and Kotlin implementations, while some versions appear as malicious Xposed modules, which interfere with application entry points.
See also: Judge pressures Apple to approve Fortnite on the App Store
SparkKitty's main goal appears to be stealing photos stored on infected devices, with a particular focus on images containing cryptocurrency wallet seed phrases.

Unlike its predecessor, SparkCat, which used optical character recognition (OCR) to selectively identify specific content, SparkKitty takes a more extensive approach, indiscriminately stealing all accessible images from device collections.
This more generalized tactic suggests that the attackers are attempting to broaden the scope of their information collection, with the goal of identifying potentially valuable financial data. The campaign exhibits geo-targeting, primarily focusing on users in Southeast Asia and China, through apps specifically designed for these regions, such as Chinese gambling games, TikTok modifications, and apps with sexual content.
See also: Google Play: Over 300 malicious apps found with 60 million downloads
Based on the above, it is clear that SparkKitty represents a new generation of malware that focuses on personal and financial data in a particularly insidious way. Targeting photos that may contain seed phrases suggests that the perpetrators are not simply looking for general information, but are seeking direct access to digital wallets and financial assets.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
