Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You

Subscribers:
7,120
Published on ● Video Link: https://www.youtube.com/watch?v=qfHlnFgw2Pk



Duration: 0:00
3 views
0


Successor to SparkCat spyware spreads via official app stores, exfiltrates gallery photos using OCR to target seed phrases.
A new strain of mobile spyware, dubbed SparkKitty, has infiltrated Apple’s App Store and Google Play, posing as crypto-themed and modded apps to stealthily extract images of seed phrases and wallet credentials.
The malware appears to be a successor to SparkCat, a campaign first uncovered in early 2025, which used fake support chat modules to silently access user galleries and exfiltrate sensitive screenshots.
SparkKitty takes the same strategy several steps further, Kaspersky researchers said in a Monday post.
Unlike SparkCat, which mostly spreads through unofficial Android packages, SparkKitty has been confirmed inside multiple iOS and Android apps available through official stores, including a messaging app with crypto exchange features (with over 10,000 installs on Google Play) and an iOS app called “币coin,” disguised as a portfolio tracker.
At the core of the iOS variant is a weaponized version of the AFNetworking or Alamofire framework, where attackers embedded a custom class that auto-runs on app launch using Objective-C’s +load selector.
On startup, it checks a hidden configuration value, fetches a command-and-control (C2) address, and scans the user’s gallery and begins uploading images. A C2 address instructs the malware on what to do, such as when to steal data or send files, and receives the stolen information back.
The Android variant utilizes modified Java libraries to achieve the same goal. OCR is applied via Google ML Kit to parse images. If a seed phrase or private key is detected, the file is flagged and sent to the attacker’s servers.
Installation on iOS is done through enterprise provisioning profiles, or a method meant for internal enterprise apps but often exploited for malware.
Victims are tricked into manually trusting a developer certificate linked to “SINOPEC SABIC Tianjin Petrochemical Co. Ltd.,” giving SparkKitty system-level permissions.
Several C2 addresses used AES-256 encrypted configuration files hosted on obfuscated servers.
Once decrypted, they point to payload fetchers and endpoints, such as/api/putImages and /api/getImageStatus, where the app determines whether to upload or delay photo transmissions.
Kaspersky researchers discovered other versions of the malware utilizing a spoofed OpenSSL library (libcrypto.dylib) with obfuscated initialization logic, indicating an evolving toolset and multiple distribution vectors.
While most apps appear to be targeted at users in China and Southeast Asia, nothing about the malware limits its regional scope.
Apple and Google have taken down the apps in question following disclosure, but the campaign has likely been active since early 2024 and may still be ongoing through side loaded variants and clone stores, researchers warned.
Read more: North Korean Hackers Are Targeting Top Crypto Firms With Malware Hidden in Job Applications
Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME,...
https://www.coindesk.com/tech/2025/06/24/saving-your-wallet-details-seed-phrase-as-a-photo-on-your-phone-this-trojan-may-be-targeting-you
#crypto #bitcoin #ethereum #cryptocurrency #news #blockchain #litecoin #cryptonews #cryptonewstoday #cryptoworld #cryptonewstoday ***NOT FINANCIAL, LEGAL, OR TAX ADVICE! JUST OPINION! I AM NOT AN EXPERT! I DO NOT GUARANTEE A PARTICULAR OUTCOME I HAVE NO INSIDE KNOWLEDGE! YOU NEED TO DO YOUR OWN RESEARCH AND MAKE YOUR OWN DECISIONS! THIS IS JUST ENTERTAINMENT!
This information is what was found publicly on the internet. This information could’ve been doctored or misrepresented by the internet. All information is meant for public awareness and is public domain. This information is not intended to slander harm or defame any of the actors involved but to show what was said through their social media accounts. Please take this information and do your own research.
bitcoin, blockchain, crypto, cryptocurrency, altcoin, investment, ethereum, bitcoin crash, xrp, cardano, ripple




Other Videos By Crypto World Daily


2025-06-24Senate GOP Unveils Bold Crypto Market Structure Principles –
2025-06-24Mastercard Expands Stablecoin Push With Paxos, Fiserv and PayPal Integrations
2025-06-24DeFi Dev Corp Launches Dogwifhat Validator: Staking Rewards Split
2025-06-24Polymarket on the Verge of Raising $200M at $1B Valuation: Report
2025-06-24ChatGPT o3’s 35-Signal AI DOGE Price Forecast Flags Bear Structure
2025-06-24Chainlink, Mastercard Tie-Up to Let Nearly 3B Cardholders Buy Crypto On-Chain
2025-06-24DOJ Alum Kevin Muhlendorf Tapped To Police SEC As Inspector
2025-06-24Strategy Stock Volatility Sinks to Historic Lows, Possibly Making Shares Less Attractive
2025-06-24Bitcoin Price Soars 2.49% on Thrilling News from Japan, Trump, and
2025-06-24CoinDesk 20 Performance Update: Chainlink (LINK) Gains 8.4%, Leading Index Higher
2025-06-23Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You
2025-06-22Washington Eyes Crypto Rules: Senate Subcommittee Hearing on
2025-06-22Michael Saylor’s Strategy Snaps Up 245 Bitcoin for $26 Million as
2025-06-22Analysts: South Korea’s Stablecoin Pivot Will Hurt Card Companies,
2025-06-22Canaan to Exit AI Chip Business, Double Down on Bitcoin Mining Amid Realignment
2025-06-22A Startup Raises $15M, Led by Paradigm, Aiming to Rival HyperLiquid
2025-06-22Bitcoin ASIC Manufacturer Canaan Drops AI Chips, Bets Big on U.S.
2025-06-22Bitcoin Price Prediction: BTC Jumps Past $105K as Israel-Iran
2025-06-22Bitcoin Reclaims $106K After Trump’s Israel-Iran Ceasefire — Is
2025-06-22HIVE Digital to Launch Canadian AI Data Hub With 7.2 MW Toronto Site Purchase
2025-06-22Brazil’s Méliuz Buys $28.6M in Bitcoin, Becomes Top Public BTC Holder in Latin America