SparkKitty malware has infiltrated Apple and Google’s app stores, and is specifically designed to steal cryptocurrency wallet mnemonic phrases.
22 hours ago
According to Check Point, cross-platform malware named SparkKitty has spread through Apple App Store, Google Play, and third-party Android app stores. The malware uses OCR (Optical Character Recognition) technology to scan images in users’ photo albums, targeting sensitive data including cryptocurrency wallet mnemonics, passwords, and QR codes. The report notes that SparkKitty is an upgraded iteration of the earlier information-stealing program SparkCat, disguised as apps such as crypto services, communication tools, and entertainment platforms for distribution. Once installed, the app requests photo album access permission, continuously scans existing and new images, and uploads the extracted text plus device information to the attacker’s server. On iOS, the malicious code was embedded in a crypto application titled “Coin” (Chinese: 币), evading Apple’s app review via code obfuscation. On Android, researchers identified the malware in “SOEX”, a chat and crypto trading app; it was pulled from Google Play only after amassing over 10,000 total downloads. Attackers also spread SparkKitty through additional channels: third-party app stores, sideloaded APKs, modified versions of TikTok, and entertainment apps. Check Point warns that if users save wallet mnemonics as screenshots or photos, their corresponding crypto wallets can be fully controlled by attackers once the mnemonics are stolen. The security agency advises against storing mnemonics in mobile photo albums—instead, they should be kept offline, such as via paper backups or hardware wallet backups. It also recommends users exercise caution when granting photo album permissions to apps and only download applications from trusted sources.
Meta and BlackRock are partnering to invest approximately $14 billion in data center development, with the facilities set to have a computing capacity of 1 gigawatt.
18 minutes ago
A newly created address withdrew 10,000 Ether from Bybit, worth approximately $18.81 million.
18 minutes ago
Morgan Stanley: After the recent pullback, the AI supply chain still boasts an attractive risk-reward ratio.
18 minutes ago
Cumberland transferred 108,090 HYPE to centralized exchanges (CEX), valued at approximately $5.95 million.
18 minutes ago
Across attacker returns 331.8 ETH to the protocol's multi-sig address, valued at approximately $623,900.
18 minutes ago
Upbit designates STORJ as a trading warning project.
18 minutes ago
Hot feeds
A trader profits $448K by monitoring #Binance's new listings!
2024.12.13 17:37:29
Last week, funds have flowed into #Bitcoin, #Ethereum, and #Hyperliquid.
2024.12.16 14:48:36
A $PEPE whale that had been dormant for 600 days transferred all 2.1T $PEPE($52M) to a new address.
2024.12.14 10:35:27
When Elon Musk tweeted about Moltbook, the meme coin MOLT experienced a short-term 30% price surge, hitting a new all-time high of $114 million.
2026.01.31 18:37:29
A smart #AI coin trader made $17.6M on $GOAT, $ai16z, $Fartcoin,$arc.
2025.01.05 16:05:18
A sniper earned 2,277 $ETH ($8.3M) trading $SHIRO within 18 hours!
2024.12.03 23:09:08
MoreHot Articles

How did I turn $1,000 into $30,000 with smart money?
2024.12.09

10 promising AI Agent cryptos
2024.12.05

The 30-Year-Old Entrepreneur Behind Virtual, a Multi-Million Dollar AI Agent Society
2025.01.22

10 smart traders specializing in MEMEcoin trading on Solana
2024.12.09

A trader lost $73.9K trading memecoins in just 3 minutes — a lesson for us all!
2024.12.13

What is $SPORE? Let us take you through the on-chain records to show you how it works.
2024.12.25

