A new variant of the SparkCat malware has been detected in apps on the Apple App Store and Google Play Store, nearly a year after the trojan was first discovered. The malware hides in seemingly innocent apps and scans victims’ photos to steal recovery phrases for crypto wallets. This development represents a significant upgrade in the malware’s capabilities and underscores the growing threat to digital asset owners.

Russian cybersecurity firm Kaspersky has discovered two infected apps on the App Store and one on the Google Play Store, targeting primarily cryptocurrency users in Asia. SparkCat uses advanced optical character recognition (OCR) technology to identify and extract images containing mnemonic phrases from victims’ photo collections. This strategy exploits the habit of many users to save screenshots of their recovery phrases, a practice considered extremely dangerous by security experts.
See also: SparkCat malware uses OCR to infiltrate crypto wallets
The iOS variant of the malware scans for cryptocurrency wallet recovery phrases in English, making it potentially broader in scope and affecting users regardless of their region. In contrast, the Android version focuses on Japanese, Korean, and Chinese keywords, indicating targeting the Asian market. This geographic specialization demonstrates the attackers’ strategic planning and understanding of local markets.
SparkCat technical improvements and hiding methods
The improved version of SparkCat for Android incorporates multiple layers of obfuscation compared to previous versions, making detection by security systems extremely difficult. It uses code virtualization and cross-platform programming languages to evade analysis efforts by security systems. The malware has been detected in applications that mimic enterprise messengers and food delivery services, categories that are usually considered trustworthy by users.
SparkCat was first detected by Kaspersky in February 2025, demonstrating its ability to leverage OCR to extract specific images containing wallet recovery phrases from photo libraries. The images are sent to servers controlled by the attackers.
Kaspersky researchers estimate that a Chinese-speaking operator, based on the characteristics of the code and the targeted languages.
See also: SparkKitty attacks iOS and Android devices through their App Stores

SparkCat uses sophisticated social engineering techniques to gain the necessary permissions from users. The infected apps request access to the photo gallery under seemingly reasonable pretexts, such as allowing image sharing or creating backups. Once access is gained, the malware begins scanning for crypto-related keywords.
Protection methods and safety recommendations
Experts recommend that users avoid storing crypto seed phrases or sensitive screenshots in their device's photo collections. Instead, they suggest using secure apps or hardware wallets. Storing mnemonic phrases on physical, offline (air-gapped) media is also considered a safe practice, as it completely eliminates the risk of digital theft.
Additionally, users should carefully consider the permissions that apps request, particularly access to photos and storage (especially if the apps are not related to image management). Downloading apps from official stores does not guarantee complete security, as SparkCat was able to bypass the control mechanisms of both Google Play and the App Store. This highlights the need for additional layers of protection beyond trusting distribution platforms.
See also: Google retires Android Instant Apps

For Android users, it is recommended to uninstall suspicious apps and scan with antivirus solutions, while for iOS users, it is recommended to check BundleIDs and monitor for unusual access to photos. Enabling app sandboxing and multi-factor authentication on cryptocurrency accounts offers additional layers of protection.
The development of SparkCat highlights the importance of using smartphone security solutions and the need for constant vigilance against evolving cyberthreats targeting cryptocurrencies. According to The Hacker News, the latest improvements to the malware demonstrate that this is an actively evolving threat that reflects the technical capabilities of threat actors. As the value of cryptocurrencies continues to increase and their adoption expands, it is expected that such attacks will become even more sophisticated and targeted.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
