Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I failed at spotting AI slop videos. Can you do better?

    I can’t believe I’m saying this, but I would buy DLC for Windows 11

    Use Microsoft Excel data types to save unnecessary typing

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      AI has become the norm for students. Teachers are playing catch-up.

      December 23, 2025

      Trump signs executive order seeking to ban states from regulating AI companies

      December 13, 2025

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025
    • Business

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025

      Zeroday Cloud hacking event awards $320,0000 for 11 zero days

      December 18, 2025

      Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

      December 18, 2025

      Want to back up your iPhone securely without paying the Apple tax? There’s a hack for that, but it isn’t for everyone… yet

      December 16, 2025
    • Crypto

      Yield Basis (YB) Gains 17% After Securing Upbit Listing

      December 26, 2025

      The Biggest Options Expiry Ever—What $27 Billion Means for Bitcoin and Ethereum

      December 26, 2025

      TRON Network Hits Record User Growth as TRX Price Faces Worst Q4 Decline

      December 26, 2025

      4chan Trader Who Nailed Bitcoin’s October All-Time High Calls $250,000 in 2026

      December 26, 2025

      Ethereum ETFs Bleed for 2 Weeks, But This Key Level Retest Could Flip the Script

      December 26, 2025
    • Technology

      I failed at spotting AI slop videos. Can you do better?

      December 26, 2025

      I can’t believe I’m saying this, but I would buy DLC for Windows 11

      December 26, 2025

      Use Microsoft Excel data types to save unnecessary typing

      December 26, 2025

      A lifetime license for this PDF editor is now only $25

      December 26, 2025

      Office + Windows 11 Pro for $40 is the best add-on to your Christmas PC

      December 26, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Malware on Google Play, Apple App Store stole your photos—and crypto
    Technology

    Malware on Google Play, Apple App Store stole your photos—and crypto

    TechAiVerseBy TechAiVerseJune 24, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Malware on Google Play, Apple App Store stole your photos—and crypto
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Malware on Google Play, Apple App Store stole your photos—and crypto

    A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices.

    The malware is a possible evolution of SparkCat, which Kaspersky discovered in January. SparkCat used optical character recognition (OCR) to steal cryptocurrency wallet recovery phrases from images saved on infected devices.

    When installing crypto wallets, the installation process tells users to write down the wallet’s recovery phrase and store it in a secure, offline location.

    Access to this seed phrase can be used to restore a crypto wallet and its stored assets on another device, making them a valuable target for threat actors.

    While taking a screenshot of your seed phrase is never a good idea, some people do so for convenience.

    A report by Kaspersky says that the new SparkKitty malware indiscriminately steals all images from an infected device’s photo gallery.

    While Kaspersky believes that the malware is targeting crypto wallet seed phrases, the stolen data could also be used for other malicious purposes, like extortion, if the images contain sensitive content.

    The SparkKitty malware

    The SparkKitty campaign has been active since at least February 2024, spreading through both official Google and Apple app stores and unofficial platforms.

    SparkKitty on Apple App Store
    Source: Kaspersky

    The malicious apps Kaspersky identified are 币coin on the Apple App Store and SOEX on Google Play, both having been removed by the time of this writing.

    SOEX is a messaging app with cryptocurrency exchange features, downloaded over 10,000 times via Android’s official app store.

    The malware app on Google Play
    Source: Kaspersky

    Kaspersky also discovered modded TikTok clones embedding fake online cryptocurrency stores, gambling apps, adult-themed games, and casino apps containing SparkKitty, distributed via unofficial channels.

    TikTok clone app installed via an iOS profile
    Source: Kaspersky

    On iOS, SparkKitty is embedded as fake frameworks (AFNetworking.framework, libswiftDarwin.dylib) and sometimes delivered via enterprise provisioning profiles.

    On Android, the malware is embedded in Java/Kotlin apps, some of which use malicious Xposed/LSPosed modules.

    The malicious framework uses the Objective-C ‘+load’ method to automatically execute its code when the app starts on iOS. A configuration check is performed by reading keys from the app’s Info.plist; execution proceeds only if values match expected strings.

    On Android, the malware is triggered on app launch or at specific user-driven actions like opening a specified screen type. Upon activation, it retrieves and decrypts a remote configuration file using AES-256 (ECB mode) to get C2 URLs.

    On iOS, the malware requests access to the photo gallery, while on Android, the malicious app requests the user to grant storage permissions to access images.

    If permission is granted on iOS, the malware monitors the gallery for changes and exfiltrates any new or previously unuploaded images.

    Image exfiltration code on the iOS variant
    Source: Kaspersky

    On Android, the malware uploads images from the gallery, along with device identifiers and metadata. Kaspersky found some SparkKitty versions that use Google ML Kit OCR to detect and only upload images containing text.

    Image exfiltration logic on Android
    Source: Kaspersky

    SparkKitty is another example of malware slipping into official app stores, highlighting once more that users shouldn’t blindly trust software on vetted distribution channels.

    All apps should be scrutinized for signs of fraud, such as fake reviews, publishers with doubtful backgrounds or histories, low downloads combined with a high number of positive reviews, etc.

    During installation, requests for storage of gallery access should be treated with suspicion and denied if they’re not related to the app’s core functionality.

    On iOS, avoid installing configuration profiles or certificates unless they come from a trusted source. On Android, enable Google Play Protect in settings and perform regular full-device scans.

    Ultimately, cryptocurrency holders should not keep images of their wallet seed phrases on their mobile devices, as these are now actively targeted by malware. Instead, store them offline in a secure location.

    BleepingComputer has contacted both Apple and Google to ask for a comment on how these apps slipped through the cracks and into their app stores.

    “The reported app has been removed from Google Play and the developer has been banned,” Google told BleepingComputer.

    “Android users are automatically protected against this app regardless of download source by Google Play Protect, which is on by default on Android devices with Google Play Services.”

    BleepingComputer also contacted Apple about the apps and will update the story if we receive a response.


    Why IT teams are ditching manual patch management

    Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

    In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous Article2026 Nissan Armada Nismo First Look: Big, Bold, But The Important Number’s Missing
    Next Article APT28 hackers use Signal chats to launch new malware attacks on Ukraine
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    I failed at spotting AI slop videos. Can you do better?

    December 26, 2025

    I can’t believe I’m saying this, but I would buy DLC for Windows 11

    December 26, 2025

    Use Microsoft Excel data types to save unnecessary typing

    December 26, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025541 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025191 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202594 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 202586 Views
    Don't Miss
    Technology December 26, 2025

    I failed at spotting AI slop videos. Can you do better?

    I failed at spotting AI slop videos. Can you do better? Image: Foundry Fake videos…

    I can’t believe I’m saying this, but I would buy DLC for Windows 11

    Use Microsoft Excel data types to save unnecessary typing

    A lifetime license for this PDF editor is now only $25

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    I failed at spotting AI slop videos. Can you do better?

    December 26, 20250 Views

    I can’t believe I’m saying this, but I would buy DLC for Windows 11

    December 26, 20250 Views

    Use Microsoft Excel data types to save unnecessary typing

    December 26, 20250 Views
    Most Popular

    What to Know and Where to Find Apple Intelligence Summaries on iPhone

    March 12, 20250 Views

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    Senua’s Saga: Hellblade 2 leads BAFTA Game Awards 2025 nominations

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.