CONTACT FOR ADS

BTCinsider – Bitcoin, Blockchain & DeFi News
  • BOOKMARKS
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
    CryptoShow More
    Bitcoin Creator Satoshi Nakamoto Is Now Richer Than Bill Gates—And Closing In on Buffett
    Bitcoin Creator Satoshi Nakamoto Is Now Richer Than Bill Gates—And Closing In on Buffett
    17.07.2025
    Man Attempts Tattoo World Record By Inking ‘Pump.fun’ on Himself 700 Times
    Man Attempts Tattoo World Record By Inking ‘Pump.fun’ on Himself 700 Times
    17.07.2025
    House Clears Key Crypto Bills for Final Vote After Record 9-Hour Standoff
    House Clears Key Crypto Bills for Final Vote After Record 9-Hour Standoff
    17.07.2025
    Whatever Happened to the Bitcoin and Ethereum Sweater Guys?
    Whatever Happened to the Bitcoin and Ethereum Sweater Guys?
    17.07.2025
    SEC Delays Decision on Bitwise Bitcoin, Ethereum ETFs' In-kind Redemptions
    SEC Delays Decision on Bitwise Bitcoin, Ethereum ETFs’ In-kind Redemptions
    17.07.2025
  • DeFi
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
    MarketShow More
    Ethereum ETFs Set Daily Record With $726 Million in Investments as ETH Soars
    Ethereum ETFs Set Daily Record With $726 Million in Investments as ETH Soars
    18.07.2025
    Bitcoin resistance at $120K hints at consolidation before impulse rally to $135K
    Bitcoin resistance at $120K hints at consolidation before impulse rally to $135K
    18.07.2025
    Nasdaq files application to add staking for BlackRock iShares ETH ETF
    Nasdaq files application to add staking for BlackRock iShares ETH ETF
    18.07.2025
    Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
    Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
    18.07.2025
    BlackRock Files With SEC to Include Staking in Ethereum ETF
    BlackRock Files With SEC to Include Staking in Ethereum ETF
    17.07.2025
  • News
    • Mining
    • NFT
    • Stocks
    • Web3
    • Tech
    NewsShow More
    Crypto holders beware: Physical attacks will hit new record in 2025 for one reason, warns Chainalysis
    Crypto holders beware: Physical attacks will hit new record in 2025 for one reason, warns Chainalysis
    17.07.2025
    Cybercriminals are about to steal more crypto in 2025 than ever before, says Chainalysis
    Cybercriminals are about to steal more crypto in 2025 than ever before, says Chainalysis
    17.07.2025
    Ethereum ETFs gobble up $720m investment record in ‘clear acceleration’ to outpace Bitcoin
    Ethereum ETFs gobble up $720m investment record in ‘clear acceleration’ to outpace Bitcoin
    17.07.2025
    Axie Infinity exec, NFT scammer testify in Roman Storm trial
    Axie Infinity exec, NFT scammer testify in Roman Storm trial
    17.07.2025
    Is ‘Ethereum season’ dawning following a 30% rally? The three reasons why Arthur Hayes says yes
    Is ‘Ethereum season’ dawning following a 30% rally? The three reasons why Arthur Hayes says yes
    16.07.2025
  • Contact Us
Reading: Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You
Share
  • bitcoinBitcoin(BTC)$120,527.45
  • ethereumEthereum(ETH)$3,476.44
  • rippleXRP(XRP)$3.51
  • tetherTether USDt(USDT)$1.00
  • binancecoinBNB(BNB)$723.63
  • solanaSolana(SOL)$175.80
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.216275
  • tronTRON(TRX)$0.316420
  • cardanoCardano(ADA)$0.82
Font ResizerAa
BTCinsider – Bitcoin, Blockchain & DeFi NewsBTCinsider – Bitcoin, Blockchain & DeFi News
  • Home
  • Crypto
  • Market
  • News
  • Tech
  • Contact
Search
  • Home
  • Market
    • Business
    • Investor
  • Tech
  • News
    • Web3
    • NFT
  • DeFi
  • Crypto
Have an existing account? Sign In
Follow US
© All Rights Reserved.
Tech

Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You

Roman Hasley
Last updated: 24.06.2025 7:31 PM
Roman Hasley
Published: 24.06.2025
Share
Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You

A new strain of mobile spyware, dubbed SparkKitty, has infiltrated Apple’s App Store and Google Play, posing as crypto-themed and modded apps to stealthily extract images of seed phrases and wallet credentials.

The malware appears to be a successor to SparkCat, a campaign first uncovered in early 2025, which used fake support chat modules to silently access user galleries and exfiltrate sensitive screenshots.

SparkKitty takes the same strategy several steps further, Kaspersky researchers said in a Monday post.

Unlike SparkCat, which mostly spreads through unofficial Android packages, SparkKitty has been confirmed inside multiple iOS and Android apps available through official stores, including a messaging app with crypto exchange features (with over 10,000 installs on Google Play) and an iOS app called “币coin,” disguised as a portfolio tracker.

(Securelist)

(Securelist)

At the core of the iOS variant is a weaponized version of the AFNetworking or Alamofire framework, where attackers embedded a custom class that auto-runs on app launch using Objective-C’s +load selector.

On startup, it checks a hidden configuration value, fetches a command-and-control (C2) address, and scans the user’s gallery and begins uploading images. A C2 address instructs the malware on what to do, such as when to steal data or send files, and receives the stolen information back.

The Android variant utilizes modified Java libraries to achieve the same goal. OCR is applied via Google ML Kit to parse images. If a seed phrase or private key is detected, the file is flagged and sent to the attacker’s servers.

Installation on iOS is done through enterprise provisioning profiles, or a method meant for internal enterprise apps but often exploited for malware.

(Securelist)

(Securelist)

Victims are tricked into manually trusting a developer certificate linked to “SINOPEC SABIC Tianjin Petrochemical Co. Ltd.,” giving SparkKitty system-level permissions.

Several C2 addresses used AES-256 encrypted configuration files hosted on obfuscated servers.

Once decrypted, they point to payload fetchers and endpoints, such as/api/putImages and /api/getImageStatus, where the app determines whether to upload or delay photo transmissions.

Kaspersky researchers discovered other versions of the malware utilizing a spoofed OpenSSL library (libcrypto.dylib) with obfuscated initialization logic, indicating an evolving toolset and multiple distribution vectors.

While most apps appear to be targeted at users in China and Southeast Asia, nothing about the malware limits its regional scope.

Apple and Google have taken down the apps in question following disclosure, but the campaign has likely been active since early 2024 and may still be ongoing through side loaded variants and clone stores, researchers warned.

BitcoinOS Sees ‘Renaissance’ for Litecoin With Its First Ever ZK Rollup
Bitcoin Core 30 to Increase OP_RETURN Data Limit After Developer Debate Concludes
Centralized AI threatens a democratic digital future
RISE Chain Secures $4M From Galaxy to Power Ultra-Fast Layer-2
Bitget and UNICEF to train 300K girls in blockchain across 8 nations

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Telegram Email Copy Link Print
Share
Previous Article Litecoin Climbs 4% to Top $84, With ETF Odds Growing Litecoin Climbs 4% to Top $84, With ETF Odds Growing
Next Article Nano Labs to issue $500M of convertible notes to fund BNB treasury Nano Labs to issue $500M of convertible notes to fund BNB treasury
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Ethereum ETFs Set Daily Record With $726 Million in Investments as ETH Soars
Ethereum ETFs Set Daily Record With $726 Million in Investments as ETH Soars
'Dogecoin Millionaire' Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
‘Dogecoin Millionaire’ Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
Performance Art Duo Operator 'Make Movement Collectible' With NFTs
Performance Art Duo Operator ‘Make Movement Collectible’ With NFTs

You Might Also Like

Trump’s World Liberty crypto tokens are set to become tradable
Tech

Trump’s World Liberty crypto tokens are set to become tradable

17.07.2025
Norway deep-sea mining firm plans $1.2B Bitcoin buy
Tech

Norway deep-sea mining firm plans $1.2B Bitcoin buy

25.06.2025
North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications
Tech

North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications

20.06.2025
Securitize, RedStone Pilot ‘Trusted Single Source Oracle’ to Secure Tokenized Fund NAVs
Tech

Securitize, RedStone Pilot ‘Trusted Single Source Oracle’ to Secure Tokenized Fund NAVs

01.07.2025

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

BTCinsider – Bitcoin, Blockchain & DeFi News

With 20 million users, we are the #1 global business blockchain and cryptocurrency news network.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up