SparkKitty malware hidden in mobile apps scans photos for crypto wallet seed phrases

Check Point detailed SparkKitty, malware hidden in mobile apps that scans photos to steal cryptocurrency wallet recovery phrases.

SparkKitty malware hidden in mobile apps scans photos for crypto wallet seed phrases

Security researchers at Check Point have detailed a newly identified strain of malware dubbed SparkKitty, designed to infiltrate mobile applications and covertly scan device photo libraries for cryptocurrency wallet seed phrases. Once embedded within compromised apps, the malware searches stored images for recovery phrases — the sequences of words used to restore access to crypto wallets — and transmits that data to malicious actors.

The discovery highlights an evolving tactic among cybercriminals targeting cryptocurrency holders. Seed phrases are among the most sensitive pieces of information a crypto user can possess, as anyone who obtains them gains full, irreversible access to the associated wallet and its funds. Storing screenshots or photos of seed phrases on mobile devices is a common practice among users, making image-scanning malware a particularly effective attack vector.

The implications for the broader crypto industry are significant. As mobile-based crypto adoption continues to grow, so does the attack surface available to bad actors. The SparkKitty campaign underscores the vulnerability of users who rely on consumer app stores without verifying application legitimacy, and raises questions about the adequacy of existing security screening processes on major mobile platforms.

Security professionals are expected to continue monitoring SparkKitty's distribution channels and any potential variants. Users are advised to avoid storing seed phrase images on internet-connected devices and to source applications exclusively from verified, trusted developers.

Source: The Block

Read original article ↗