Kaspersky researchers have uncovered SparkKitty, a cross-platform mobile spyware campaign targeting Android and iOS users through trojanized cryptocurrency, gambling, and TikTok-themed applications.
The malware steals photos and device information, with attackers believed to be searching for cryptocurrency wallet recovery phrases, passwords, and other sensitive content stored in image galleries.
SparkKitty has been active since at least February 2024 and is believed to be linked to the earlier SparkCat campaign.
Both threats use malicious components hidden inside otherwise functional applications, demonstrating how threat actors can abuse trusted distribution channels as well as unofficial download sites.
SparkKitty Targets Crypto Wallets
On iOS, Kaspersky identified SparkKitty in a cryptocurrency-related application named 币coin, which was available through Apple’s App Store before being removed.
Researchers also found malicious TikTok and gambling app variants distributed through phishing pages that impersonated the App Store.
These pages instructed victims to install developer provisioning profiles, allowing the malicious apps to run outside Apple’s normal App Store distribution model.
The fake TikTok apps embedded links to a suspicious shopping platform that accepted cryptocurrency payments only.
More importantly, the iOS variants requested access to the victim’s photo library, an unusual permission request for a TikTok clone.
Kaspersky found malicious modules masquerading as legitimate frameworks, including AFNetworking.framework and Alamofire. framework, as well as obfuscated libraries using names such as libswiftDarwin.dylib.
The malicious iOS framework used an automatically executed Objective-C load method to activate its spyware functions.
It retrieved encrypted configuration data, decrypted command-and-control (C2) addresses, contacted an attacker-controlled server for authorization, and then uploaded accessible gallery images with app, device, and unique user information.
Android users were targeted through Google Play, third-party websites, and directly downloadable APK files.
One identified app, SOEX, presented itself as a messenger with cryptocurrency exchange features and exceeded 10,000 downloads on Google Play before Google removed it following notification from Kaspersky.
Other Android variants were promoted as cryptocurrency investment services, casino applications, and modified TikTok packages.
Some samples were implemented in Java, while a Kotlin-based variant operated as a malicious Xposed or LSPosed module, enabling it to hook into application execution paths.
SparkKitty’s primary capability is gallery exfiltration. After receiving permission, the malware monitors or accesses photos on an infected device and sends them to its C2 infrastructure.
Many observed variants steal all accessible images rather than selecting only specific files, creating a broad privacy and security risk beyond cryptocurrency theft, cyberint said.
A related activity cluster identified by Kaspersky used Google ML Kit optical character recognition to inspect JPEG and PNG files. The code searched images for text and uploaded pictures that matched its selection criteria.
This behavior resembles SparkCat’s OCR-based search for cryptocurrency recovery phrases, but researchers note that widespread image theft not OCR filtering was the main behavior observed across SparkKitty samples.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.