Kaspersky Identifies SparkKitty Trojan Threat in Crypto Apps

Kaspersky researchers have identified a new malware, ‘SparkKitty,’ targeting cryptocurrency users through apps in Southeast Asia and China as of June 2025.

The malware poses a serious threat to crypto wallet security, particularly for Bitcoin and Ethereum users, capitalizing on stored screenshots of wallet recovery phrases.

‘SparkKitty’ Malware Exploits App Store Security Gaps

Kaspersky detects the ‘SparkKitty’ trojan, targeting crypto users by exploiting stored wallet recovery phrases. The malware infiltrates apps, leveraging trusted platforms like Google Play and the App Store, underscoring a security gap.

Researchers at Kaspersky highlight that both iOS and Android users are vulnerable. The SparkKitty malware follows in the wake of SparkCat, reinforcing concerns over app store security and user data protection. “SparkKitty takes advantage of users storing screenshots of their crypto wallet recovery phrases, making both iOS and Android users vulnerable through seemingly legitimate apps distributed via trusted stores.”

User Concerns Rise Amid Lack of Platform Responses

The SparkKitty trojan threatens financial assets by accessing recovery phrases stored in image galleries. Despite Kaspersky’s notification, no official comments have been made by major platforms like Apple or Google, heightening user concerns.

Regulatory bodies have yet to react publicly to the SparkKitty threat. Previous incidents, such as SparkCat, highlight the growing risk of mobile crypto security breaches and the need for enhanced protective measures.

Security Loophole Exposes Digital Asset Risks

The SparkKitty trojan correlates with earlier threats like SparkCat, which also compromised crypto users’ wallet data through app store breaches. These incidents demonstrate a persistent security loophole in digital asset protection.

Analysts suggest that unless robust security measures are implemented by app platforms, similar malware will continue to threaten crypto holders. The industry must prioritize safe data practices to safeguard digital assets.

Disclaimer: This website provides information only and is not financial advice. Cryptocurrency investments are risky. We do not guarantee accuracy and are not liable for losses. Conduct your own research before investing.
Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments