logo

Malware on Google Play, Apple App Store stole your photos—and crypto

ID: 78b85cdd-10dc-543f-a5d7-12e5b11f304a

STIX ID: report--78b85cdd-10dc-543f-a5d7-12e5b11f304a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-06-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky and BleepingComputer reported a cross‑platform mobile malware campaign (SparkKitty) active since at least February 2024 that infiltrated official and unofficial app stores; the malicious apps request gallery/storage access, exfiltrate images (sometimes using OCR/Google ML Kit to detect text) and aim to steal cryptocurrency wallet recovery phrases and other sensitive photos—apps identified (SOEX, 币coin) have been removed and users are advised to deny gallery access, avoid storing seed phrases as images, and scrutinize apps and provisioning profiles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.