SparkCat malware variant expands OCR-based crypto recovery phrase theft to iOS and enhanced Android targets
Summary
Hide ▲
Show ▼
A newly identified variant of the SparkCat malware has been observed on the Apple App Store and Google Play Store, camouflaged within legitimate-looking applications such as enterprise messengers and food delivery services. The malware specifically targets cryptocurrency users by scanning mobile device photo galleries for images containing wallet recovery phrases using optical character recognition (OCR). The iOS version scans for English mnemonics, broadening its potential geographic impact, while the Android iteration focuses on Japanese, Korean, and Chinese keywords. Exfiltrated images are sent to attacker-controlled servers.
Timeline
-
03.04.2026 12:10 1 articles · 3h ago
SparkCat malware variant with OCR-based wallet recovery phrase theft identified on iOS and enhanced Android applications
SparkCat malware has evolved into a cross-platform threat targeting cryptocurrency users via mobile applications on Apple App Store and Google Play Store. The iOS variant scans photo galleries for wallet recovery phrase images containing English mnemonics, while the Android version incorporates improved obfuscation and targets Asian languages (Japanese, Korean, Chinese). OCR is used to analyze images, and matching files are exfiltrated to attacker-controlled infrastructure. Initial assessment links the campaign to a Chinese-speaking threat actor, highlighting the ongoing operational activity of SparkCat since its initial documentation in early 2025.
Show sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
Information Snippets
-
The malware has been concealed within apps such as enterprise messengers and food delivery services available on both Apple App Store and Google Play Store.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
The iOS variant scans for wallet recovery phrase images containing English mnemonics, increasing its potential victim base beyond regional language constraints.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
The Android variant incorporates enhanced obfuscation techniques, including code virtualization and cross-platform programming languages, to evade detection and analysis.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
The Android version specifically searches for wallet recovery phrase images containing keywords in Japanese, Korean, and Chinese, indicating an Asia-focused targeting strategy.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
SparkCat uses OCR to analyze text within stored images in the device gallery and exfiltrates images containing relevant keywords to attacker-controlled servers.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
SparkCat was first documented by Kaspersky in February 2025 and attributed to a Chinese-speaking threat actor based on prior assessment.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10
-
The malware requests photo gallery access under certain scenarios, similar to the initial Trojan version, to perform its scanning activities.
First reported: 03.04.2026 12:101 source, 1 articleShow sources
- New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images — thehackernews.com — 03.04.2026 12:10