Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You
SparkKitty, a sophisticated mobile spyware campaign, has infiltrated both Apple’s App Store and Google Play, targeting cryptocurrency users. This malware, a significant advancement over its predecessor SparkCat, disguises itself within seemingly legitimate crypto-related apps. SparkCat primarily spread through unofficial Android channels, but SparkKitty demonstrates a more advanced distribution strategy, leveraging official app stores to reach a wider audience.
Researchers at Kaspersky have detailed the malware’s operation. They’ve identified infected apps, including a messaging app with crypto exchange features (boasting over 10,000 Google Play installs) and an iOS app, “币coin,” posing as a portfolio tracker. The iOS variant cleverly weaponizes the AFNetworking or Alamofire framework, embedding a custom class that automatically executes upon app launch. This class checks a hidden configuration value, retrieves a command-and-control (C2) server address, and initiates a scan of the user’s image gallery. Images are then uploaded to the C2 server, which dictates data theft and file transmission schedules. The Android variant employs modified Java libraries to achieve similar functionality.
SparkKitty employs Optical Character Recognition (OCR) via Google ML Kit to analyze images, specifically identifying and flagging seed phrases or private keys for transmission to the attackers. The iOS installation process involves exploiting enterprise provisioning profiles, tricking users into trusting a developer certificate associated with “SINOPEC SABIC Tianjin Petrochemical Co. Ltd.,” granting SparkKitty extensive system-level permissions. The C2 servers utilize AES-256 encrypted configuration files, further obscuring their operation. Researchers found variations using a spoofed OpenSSL library (libcrypto.dylib), suggesting an adaptable and evolving threat.
While the affected apps initially appeared to target users in China and Southeast Asia, the malware’s capabilities are not geographically limited. Although Apple and Google have removed the identified malicious apps, the campaign’s activity likely extends back to early 2024 and may persist through side-loaded versions and unofficial app stores. Users are urged to exercise caution when downloading crypto-related applications, verifying developers and scrutinizing app permissions before installation.

