Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SparkKitty Targets Crypto Users via Photo Scanning

SparkKitty Targets Crypto Users via Photo Scanning

Posted on July 27, 2026 By CWS

SparkKitty: New Threat to Crypto Users

A novel malware, SparkKitty, is posing a significant risk to cryptocurrency users by exploiting photos stored on mobile devices. This malware, affecting both iOS and Android platforms, specifically targets wallet seed phrases concealed within screenshots and image galleries. Instead of traditional methods like keystroke logging, SparkKitty employs optical character recognition (OCR) to extract text from images.

Infiltration through App Marketplaces

SparkKitty has infiltrated official app marketplaces, putting unsuspecting users at risk. Once installed, the malware requests access to photos and scans for sensitive information, sending it to servers under attacker control. Check Point researchers have traced this malware’s spread through apps disguised as legitimate cryptocurrency, messaging, and entertainment tools.

Evolution from Previous Threats

This malware is an evolution of SparkCat, an earlier threat. Similar OCR-based attacks have grown more common, highlighting the danger posed by leaked seed phrases, which can allow criminals to empty crypto wallets swiftly. Victims often remain unaware until their funds are missing, as the malware operates silently after gaining gallery access.

How SparkKitty Exploits Photos

Targeting the Photo Gallery

SparkKitty treats photo galleries as repositories of financial secrets. Many users store recovery phrases for convenience, making them easy targets. After obtaining permission, the malware continuously monitors the gallery, utilizing OCR to scan both new and existing images.

App Disguises and Distribution

On iOS, SparkKitty was hidden within an app called “币coin” on the App Store, while on Android, an app named “SOEX” masqueraded as a messaging platform, achieving over 10,000 downloads before removal. Variants have also been found in third-party stores and modded applications.

Preventive Measures and Security Tips

Minimizing Risk Exposure

To protect against SparkKitty, users should avoid installing apps from untrusted sources and deny gallery access unless necessary. Storing seed phrases as photos is particularly risky. Instead, consider hardware wallets or offline backups in secure locations.

Maintaining Vigilant Security Practices

Regularly updating devices, reviewing app permissions, and promptly removing apps that request excessive access are crucial steps. In case of suspected infection, disconnect from networks, transfer funds using a clean device, and update related credentials.

Conclusion

SparkKitty highlights the vulnerabilities in photo storage habits, urging crypto users to adopt safer practices. By staying informed and cautious, users can guard their digital assets against this and similar threats.

Cyber Security News Tags:Android, app marketplaces, app security, Check Point Research, crypto theft, crypto wallets, Cybersecurity, IOS, Malware, mobile security, OCR technology, photo scanning, seed phrases, SparkKitty, Trojanized apps

Post navigation

Previous Post: DentaQuest Data Breach Affects Millions Nationwide
Next Post: GitHub Introduces Dependabot Cooldown to Curb Threats

Related Posts

Germany Urges Apple, Google to Block Chinese AI App DeepSeek Over Privacy Rules Germany Urges Apple, Google to Block Chinese AI App DeepSeek Over Privacy Rules Cyber Security News
GitLab Releases Critical Security Updates to Fix Vulnerabilities GitLab Releases Critical Security Updates to Fix Vulnerabilities Cyber Security News
Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails Cyber Security News
25 Controls, Mapped And Audit-Ready 25 Controls, Mapped And Audit-Ready Cyber Security News
Spotify Launches Direct Message Feature for Music Sharing, What are the Risks Associated? Spotify Launches Direct Message Feature for Music Sharing, What are the Risks Associated? Cyber Security News
TuxBot v3 Botnet Threatens IoT Devices Globally TuxBot v3 Botnet Threatens IoT Devices Globally Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Boosts File Explorer Speed for Large Deletions
  • Anthropic’s Opus 5: A Budget-Friendly Cybersecurity Model
  • GitHub Introduces Dependabot Cooldown to Curb Threats
  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Boosts File Explorer Speed for Large Deletions
  • Anthropic’s Opus 5: A Budget-Friendly Cybersecurity Model
  • GitHub Introduces Dependabot Cooldown to Curb Threats
  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark