logo

SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play

ID: 8326e87a-bdfa-5601-ad3d-2cfc75e23099

STIX ID: report--8326e87a-bdfa-5601-ad3d-2cfc75e23099

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-06-23

Date Updated: 2026-04-29

Author: Sergey Puzan, Dmitry Kalinin

...
...

Kaspersky researchers uncovered a cross‑platform spyware campaign (SparkKitty, linked to SparkCat) active since at least Feb 2024 that delivered malicious iOS frameworks and Android Trojans (including Kotlin Xposed modules) via official app stores and third‑party downloads; the malware requests gallery access, uses OCR and AES‑encrypted C2 configurations to exfiltrate images (likely targeting crypto wallet seed phrases), is obfuscated and persisted across many samples, and the report contains detailed indicators of compromise (file hashes, C2 addresses, config URLs) and observable TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.