Hackers Steal Crypto Wallet Seed Phrases from Image Galleries

cryptonews.ruОпубліковано о 2026-07-27Востаннє оновлено о 2026-07-27

Анотація

A new type of malware called SparkKitty is using optical character recognition (OCR) to steal cryptocurrency wallet seed phrases directly from photos and screenshots in a device's gallery, bypassing traditional keylogging defenses. Once installed from malicious apps posing as legitimate crypto services on the Apple App Store and Google Play, it requests photo access, scans images for confidential data like passwords and seeds, and sends it to hackers' servers. Control of a seed phrase gives attackers complete access to drain the wallet. Initially detected as SparkCat, the evolved SparkKitty was found in the iOS app 币coin (hiding in obfuscated code) and the Android app SOEX (downloaded over 10,000 times). This method allows theft even when sensitive data is never typed or copied. The report comes alongside news of other attacks, like a method to hijack Telegram Desktop sessions bypassing 2FA.

After installation, the infected program requests access to photos, scans images for confidential information, and sends the results to remote servers controlled by attackers. SparkKitty does not use traditional data interception methods, such as keylogging or clipboard tracking, but rather optical character recognition (OCR) technology to extract text directly from photos and screenshots. This allows it to bypass standard security systems and steal passwords, seed phrases, and other secret data, even if they are not entered via the keyboard or copied to the clipboard, explained Check Point analysts.

If attackers obtain a seed phrase, they gain full control of the crypto wallet and can empty it in a matter of minutes. The malicious program operates covertly in the background, so the device owner may not immediately notice the theft of funds—until they log into their crypto wallet.

The malicious program was first discovered by Kaspersky experts in early 2024 under the name SparkCat. But now the program has changed. The creators of SparkKitty have started distributing it more frequently in the Apple App Store and Google Play under the guise of applications mimicking legitimate cryptocurrency services, messengers, and entertainment services. This has significantly increased the likelihood of installation by unsuspecting users.

For iOS devices, the malicious program was embedded in the cryptocurrency app "币coin" and uploaded to the App Store. It remains unclear whether the developer account was hacked or if the developer is aware of the infection. The app managed to bypass Apple's security review by hiding malicious code within obfuscated frameworks AFNetworking and libswiftDarwin.dylib. These modules were crafted so that the app appeared legitimate, allowing SparkKitty to evade detection, explained Check Point specialists.

The Android version was distributed through the SOEX app, which was downloaded over 10,000 times from Google Play. The app posed as a messaging and cryptocurrency platform but allowed hackers to access multimedia storage on smartphones and other devices, track file changes, and steal data.

Recently, experts from SlowMist discovered a new method hackers use to intercept Telegram Desktop sessions, bypass two-factor authentication (2FA), and steal crypto wallet data. Recently, the CEO of the financial platform Robinhood, Vlad Tenev, was targeted—his X (formerly Twitter) account was hacked to promote the meme coin VLAD.

Пов'язані питання

QWhat is the name of the new malware that steals seed phrases from cryptocurrency wallets using OCR technology?

ASparkKitty

QWhat is the primary technique used by the SparkKitty malware to steal sensitive information, and why is it effective?

AIt uses Optical Character Recognition (OCR) to extract text directly from photos and screenshots. This is effective because it bypasses standard security systems by stealing data that is not typed on a keyboard or copied to the clipboard.

QWhich major app stores are mentioned as distribution channels for the disguised SparkKitty malware?

AApple App Store and Google Play

QWhat was the method used by the iOS version of SparkKitty to hide its malicious code and evade Apple's security checks?

AIt hid the malicious code in obfuscated frameworks, specifically AFNetworking and libswiftDarwin.dylib.

QWhat other recent attack vector, unrelated to SparkKitty, is mentioned where hackers bypassed Telegram Desktop's two-factor authentication?

AExperts from SlowMist discovered a new method hackers use to hijack Telegram Desktop sessions, bypassing two-factor authentication (2FA) to steal cryptocurrency wallet data.

Пов'язані матеріали

In Jinjiang, Fujian, a Storage Super Unicorn Lies Quiet

In Fujian's Jinjiang, a city known for sportswear, lies a quiet semiconductor giant: Fujian Jinhua Integrated Circuit Co. (JHICC). Once a promising domestic DRAM manufacturer alongside Yangtze Memory and ChangXin Memory Technologies (CXMT), its journey was derailed in 2018 when the U.S. placed it on an Entity List and filed criminal charges for alleged trade secret theft. This halted production for years. A turning point came in February 2024 when a U.S. federal court found JHICC not guilty. However, it had lost crucial time. While CXMT soared to become a top-valued A-share company in 2024, JHICC, with an estimated valuation of 80 billion RMB, was just restarting. Its current output is primarily customized DDR4 chips, not the advanced DDR5/HBM demanded for AI, but it still benefits from the broader memory chip upcycle. JHICC's story is tied to Chen Zhengkun, a veteran engineer who left Micron to lead the venture. Founded in 2016 with state-backed funding, JHICC partnered with Taiwan's UMC to develop DRAM technology. Rapid progress was cut short by the U.S. actions, which Micron initiated, partly due to its heavy reliance on the Chinese market. Post-sanctions, Chen's team worked to rebuild the production line with reduced reliance on U.S. technology. According to its records, JHICC achieved small-scale production and revenue growth under immense pressure. It now focuses on the stable "niche" DRAM market (e.g., TVs, routers) with a monthly capacity of ~40,000 wafers, aiming for 60,000 by 2026. It holds over 1,000 patents but remains on the Entity List. For Jinjiang, investing in JHICC was a bold industrial leap. The local government provided unwavering financial and logistical support during the crisis, helping the company survive. JHICC has become the anchor for a growing local semiconductor cluster. Though its scale lags behind domestic peers, JHICC's persistence symbolizes a hard-won foothold in a global market long dominated by Samsung, SK Hynix, and Micron. Having missed one boom, it seeks a place in the new AI-driven memory supercycle.

marsbit27 хв тому

In Jinjiang, Fujian, a Storage Super Unicorn Lies Quiet

marsbit27 хв тому

Must-Watch Events Next Week|CLARITY Act Could Face Senate Vote; SpaceX, Circle to Report Earnings (8.3-8.9)

**Summary: Key Events and Developments to Watch (August 3-9)** The upcoming week is marked by significant financial disclosures, key legislative deadlines, and notable product updates. **Major Financial Events:** Several companies are scheduled to release their Q2 2026 earnings. American Bitcoin (ABTC) will report on August 3, followed by SpaceX and Hut 8 Mining Corp. on August 4, and Circle on August 5. Notably, a significant portion of SpaceX shares (up to 12% of total shares) will be unlocked on August 6 following their earnings release. **Key Legislative Deadline:** The U.S. Senate faces an August 7 deadline to secure 60 votes for the CLARITY Act, a bipartisan bill aiming to establish a federal regulatory framework for cryptocurrencies. The Senate may hold a full vote on the bill during the week. **Economic Data:** The U.S. July Non-Farm Payrolls report will be released on August 7, providing crucial labor market data. **Technology & Product Updates:** * **Shutdowns:** DeFi portfolio tracker Zapper and wallet app Ctrl Wallet will cease operations on August 3. * **Upgrades:** LayerZero will deprecate its v1 relayers on August 3. XRP Ledger's new version 3.3.0, featuring five new functions, is expected next week. * **AI:** Elon Musk announced that the advanced Grok 4.6 AI model is set for release around August 7. * **Bitcoin:** The BIP-110 forced signaling for a potential Bitcoin network change is scheduled to begin around August 8. **Other Notable Events:** Chinese robotics firm Unitree Tech has set its preliminary price inquiry for its IPO for August 5. South Korean exchange Upbit will delist AQT and AERGO tokens on August 3.

marsbit2 год тому

Must-Watch Events Next Week|CLARITY Act Could Face Senate Vote; SpaceX, Circle to Report Earnings (8.3-8.9)

marsbit2 год тому

Торгівля

Спот
活动图片