Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Google is sunsetting the weather app on Android

    Nvidia could launch its first laptops with its own processors later this year

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026
    • Crypto

      XRP Struggles as On-Chain Stress Mounts: Is a Bottom Forming?

      February 23, 2026

      Vitalik Buterin Sold Over 8,800 ETH in February: Did It Impact the Price?

      February 23, 2026

      Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

      February 23, 2026

      Ethereum, Solana Defy L1 Myth — Bitwise CIO Sees Prediction Markets Changing Everything

      February 23, 2026

      5 Critical Factors That Could End Gold’s 7-Month Green Streak

      February 23, 2026
    • Technology

      Google is sunsetting the weather app on Android

      February 23, 2026

      Nvidia could launch its first laptops with its own processors later this year

      February 23, 2026

      AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

      February 23, 2026

      Here’s your chance to grab a cheaper Cybertruck but you have to hurry

      February 23, 2026

      Rocket reentries are leaving measurable lithium pollution in the upper atmosphere

      February 23, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Malware on Google Play, Apple App Store stole your photos—and crypto
    Technology

    Malware on Google Play, Apple App Store stole your photos—and crypto

    TechAiVerseBy TechAiVerseJune 24, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Malware on Google Play, Apple App Store stole your photos—and crypto
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Malware on Google Play, Apple App Store stole your photos—and crypto

    A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices.

    The malware is a possible evolution of SparkCat, which Kaspersky discovered in January. SparkCat used optical character recognition (OCR) to steal cryptocurrency wallet recovery phrases from images saved on infected devices.

    When installing crypto wallets, the installation process tells users to write down the wallet’s recovery phrase and store it in a secure, offline location.

    Access to this seed phrase can be used to restore a crypto wallet and its stored assets on another device, making them a valuable target for threat actors.

    While taking a screenshot of your seed phrase is never a good idea, some people do so for convenience.

    A report by Kaspersky says that the new SparkKitty malware indiscriminately steals all images from an infected device’s photo gallery.

    While Kaspersky believes that the malware is targeting crypto wallet seed phrases, the stolen data could also be used for other malicious purposes, like extortion, if the images contain sensitive content.

    The SparkKitty malware

    The SparkKitty campaign has been active since at least February 2024, spreading through both official Google and Apple app stores and unofficial platforms.

    SparkKitty on Apple App Store
    Source: Kaspersky

    The malicious apps Kaspersky identified are 币coin on the Apple App Store and SOEX on Google Play, both having been removed by the time of this writing.

    SOEX is a messaging app with cryptocurrency exchange features, downloaded over 10,000 times via Android’s official app store.

    The malware app on Google Play
    Source: Kaspersky

    Kaspersky also discovered modded TikTok clones embedding fake online cryptocurrency stores, gambling apps, adult-themed games, and casino apps containing SparkKitty, distributed via unofficial channels.

    TikTok clone app installed via an iOS profile
    Source: Kaspersky

    On iOS, SparkKitty is embedded as fake frameworks (AFNetworking.framework, libswiftDarwin.dylib) and sometimes delivered via enterprise provisioning profiles.

    On Android, the malware is embedded in Java/Kotlin apps, some of which use malicious Xposed/LSPosed modules.

    The malicious framework uses the Objective-C ‘+load’ method to automatically execute its code when the app starts on iOS. A configuration check is performed by reading keys from the app’s Info.plist; execution proceeds only if values match expected strings.

    On Android, the malware is triggered on app launch or at specific user-driven actions like opening a specified screen type. Upon activation, it retrieves and decrypts a remote configuration file using AES-256 (ECB mode) to get C2 URLs.

    On iOS, the malware requests access to the photo gallery, while on Android, the malicious app requests the user to grant storage permissions to access images.

    If permission is granted on iOS, the malware monitors the gallery for changes and exfiltrates any new or previously unuploaded images.

    Image exfiltration code on the iOS variant
    Source: Kaspersky

    On Android, the malware uploads images from the gallery, along with device identifiers and metadata. Kaspersky found some SparkKitty versions that use Google ML Kit OCR to detect and only upload images containing text.

    Image exfiltration logic on Android
    Source: Kaspersky

    SparkKitty is another example of malware slipping into official app stores, highlighting once more that users shouldn’t blindly trust software on vetted distribution channels.

    All apps should be scrutinized for signs of fraud, such as fake reviews, publishers with doubtful backgrounds or histories, low downloads combined with a high number of positive reviews, etc.

    During installation, requests for storage of gallery access should be treated with suspicion and denied if they’re not related to the app’s core functionality.

    On iOS, avoid installing configuration profiles or certificates unless they come from a trusted source. On Android, enable Google Play Protect in settings and perform regular full-device scans.

    Ultimately, cryptocurrency holders should not keep images of their wallet seed phrases on their mobile devices, as these are now actively targeted by malware. Instead, store them offline in a secure location.

    BleepingComputer has contacted both Apple and Google to ask for a comment on how these apps slipped through the cracks and into their app stores.

    “The reported app has been removed from Google Play and the developer has been banned,” Google told BleepingComputer.

    “Android users are automatically protected against this app regardless of download source by Google Play Protect, which is on by default on Android devices with Google Play Services.”

    BleepingComputer also contacted Apple about the apps and will update the story if we receive a response.


    Why IT teams are ditching manual patch management

    Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

    In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous Article2026 Nissan Armada Nismo First Look: Big, Bold, But The Important Number’s Missing
    Next Article APT28 hackers use Signal chats to launch new malware attacks on Ukraine
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Google is sunsetting the weather app on Android

    February 23, 2026

    Nvidia could launch its first laptops with its own processors later this year

    February 23, 2026

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    February 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025690 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025278 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025159 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025120 Views
    Don't Miss
    Technology February 23, 2026

    Google is sunsetting the weather app on Android

    Google is sunsetting the weather app on Android Google is replacing the long-standing shortcut with…

    Nvidia could launch its first laptops with its own processors later this year

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    Here’s your chance to grab a cheaper Cybertruck but you have to hurry

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Google is sunsetting the weather app on Android

    February 23, 20262 Views

    Nvidia could launch its first laptops with its own processors later this year

    February 23, 20261 Views

    AMD reportedly pauses Ryzen Z1 drivers for gaming handhelds

    February 23, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.