Just in:
ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // India rebuts Musk allegations over Starlink launch delay // Malicious GitHub workflows expose credentials across hundreds of repositories // Saudi Arabia and UAE endorse Japan’s Asian oil initiative // OpenAI extends GPT-6 access with interactive ChatGPT interface // Anti-Election Commission Protest: Athletic Rahul Steals The Show // Dubai property sales slump as war pressures prices // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // Abu Dhabi climate summit records over 1,000 registrations // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // UAE delegation heads to Bangkok for IMF meetings // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // React flaw exposes Next.js servers to service disruption // Wikimedia identifies unauthorised OpenAI agent activity across platforms // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // India establishes 5.56 km open-air quantum security link // Lufthansa and three airlines halt Riyadh flight operations //

SparkKitty turns mobile photo libraries into theft targets

Cybersecurity researchers have renewed warnings over SparkKitty, a cross-platform mobile Trojan that steals photographs from compromised Android and iOS devices and transfers them to attacker-controlled command servers.

The malware targets images that may expose cryptocurrency wallet recovery phrases, passwords, identity documents, QR codes and financial information. Its ability to capture entire photo libraries also creates risks beyond digital-asset theft, including account takeover, identity fraud, surveillance and extortion.

SparkKitty was first documented in June 2025 after being found inside applications distributed through Apple’s App Store, Google Play and third-party websites. Evidence from malware samples indicates that the operation had been active since at least February 2024.

The campaign has primarily targeted users in China and Southeast Asia, particularly people using cryptocurrency trading services and mobile wallets. However, distribution through official application stores increased the potential exposure beyond those markets.

Most SparkKitty versions do not analyse photographs on the infected device. Instead, they indiscriminately upload accessible images for examination by the operators. A related cluster uses optical character recognition to select pictures containing potentially valuable text before exfiltration.

That distinction separates much of SparkKitty’s activity from SparkCat, an earlier mobile stealer linked to the same threat operation. SparkCat deployed optical character recognition models to search images for words associated with cryptocurrency seed phrases and upload selected files.

Technical similarities between the two campaigns include shared infrastructure patterns, cryptocurrency-themed applications, malicious software development kits and the theft of gallery content. Investigators assess that SparkKitty is likely connected to SparkCat rather than being an unrelated malware family.

A seed phrase usually consists of 12 or 24 words that can restore access to a cryptocurrency wallet. Anyone possessing the phrase may be able to recreate the wallet on another device and transfer its assets without knowing the owner’s password.

SparkKitty exploits the practice of saving seed phrases as screenshots. Users also frequently store photographs of passports, driving licences, bank cards, medical records and handwritten passwords, turning a phone’s gallery into a concentrated repository of sensitive information.

On Android, one prominent infected application was SOEX, which presented itself as a messaging service with cryptocurrency exchange functions. The application was downloaded more than 10,000 times through Google Play before it was removed.

Other Android versions were promoted as cryptocurrency investment platforms or distributed through modified TikTok applications and unofficial download pages. Some were advertised through social media and video platforms to direct potential victims towards sideloaded installation files.

The Android payload appeared in Java and Kotlin variants. One Kotlin version operated as a malicious Xposed module, a format associated with software capable of modifying system and application behaviour on rooted or altered devices.

After installation, the malicious code requested access to device storage or media files. Applications containing the Trojan often continued to provide their advertised functions, reducing the likelihood that victims would immediately suspect malicious activity.

Once permission was granted, SparkKitty collected existing images and monitored the gallery for new files. The malware also transmitted device information that could help operators identify victims, manage infections and organise stolen material.

On iOS, the campaign used an application branded 币coin, presented as a cryptocurrency service. The malicious application reached Apple’s App Store before being removed on June 25, 2025, two days after the threat was publicly documented.

Other iPhone infections were delivered through websites designed to resemble Apple’s official marketplace. These sites used legitimate developer distribution mechanisms to persuade users to install applications presented as TikTok modifications, gambling platforms or cryptocurrency tools.

The iOS payload was concealed in malicious frameworks that imitated widely used networking libraries, including components resembling AFNetworking and Alamofire. Other samples disguised malicious code as a Swift system library or embedded it directly within an application.

Command-and-control addresses were sometimes stored in cloud-based configuration files, allowing operators to change server locations without rebuilding the infected application. This technique can complicate detection and help maintain access when malicious infrastructure is blocked.

The campaign shows how criminals are adapting to stronger mobile security controls. Rather than attempting to defeat wallet encryption directly, attackers exploit permissions willingly granted to apparently legitimate applications and search material that users have stored for convenience.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // India rebuts Musk allegations over Starlink launch delay // UK and allies expose Integrity Tech cyber operations // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Global condemnation widens over deadly Saudi airport strikes // UAE delegation heads to Bangkok for IMF meetings // Dubai property sales slump as war pressures prices // Anti-Election Commission Protest: Athletic Rahul Steals The Show // Gold reaches weekly peak as oil prices retreat // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // OpenAI extends GPT-6 access with interactive ChatGPT interface // Abu Dhabi launches AI training to accelerate government transformation // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // India establishes 5.56 km open-air quantum security link // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // Malicious GitHub workflows expose credentials across hundreds of repositories //