SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App Store and Google Play
SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to (TL-2026-1717), also tracked as SparkKitty, is a high-severity malware campaign, first published 2026-07-27. It has no confirmed attribution, affects Apple App Store (iOS) -- trojanized applications including "币coin" and, maps to 16 MITRE ATT&CK techniques (T1406, T1409, T1426), and is covered by 9 detection rules and 58 indicators of compromise.
Key facts for TL-2026-1717
- Threat ID
- TL-2026-1717
- Also known as
- SparkKitty
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-27
- Last reviewed
- 2026-07-27
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, financial services, consumer general public, gambling, social media
- Target regions
- china, Southeast Asia, Global (secondary exposure)
- Detection rules
- 9
- Indicators of compromise
- 58
Malware and tooling in SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
Malware and tooling: SparkCat, Easemob HelpDesk SDK, Google ML Kit, HikariLLVM, LSPosed/Xposed, libmodsvmp.so
SparkKitty is a cross-platform mobile stealer distributed via the Apple App Store, Google Play, and third-party/sideloaded APK sites, hidden inside trojanized apps -- including the iOS crypto-wallet app "币coin" and the Android messaging/crypto-exchange app "SOEX" (10,000+ installs) -- that uploads device photo-gallery images (in some variants filtered via Google ML Kit OCR) to attacker C2 infrastructure to harvest cryptocurrency wallet seed phrases and recovery codes. It is Kaspersky-assessed as the successor to the SparkCat trojan (Securelist, January 2025), reusing its OCR-based theft technique and sharing infected-app overlap.
How SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to works
SparkKitty is a cross-platform (iOS + Android) mobile stealer, first publicly disclosed by Kaspersky/Securelist on 2025-06-23, that has been active since at least February 2024, primarily against users in China and Southeast Asia. Unlike its assessed predecessor SparkCat -- which selectively OCR-filtered gallery images for wallet-recovery keywords using Google ML Kit -- some SparkKitty variants indiscriminately exfiltrate the entire photo gallery, while others retain the ML Kit OCR text-filtering approach to prioritize images containing recoverable text (seed phrases, recovery words, 2FA backup codes, exchange screenshots).
Distribution is multi-vector and abuses both official and unofficial channels. On iOS, the malware reached the App Store hidden inside "币coin," a fake cryptocurrency portfolio/tracker app, and was also distributed outside App Store review entirely via an abused Apple Developer enterprise/ad-hoc provisioning profile (certificate EHQ3N2D5WH, issued to "SINOPEC SABIC Tianjin Petrochemical Co. Ltd.," profile UUID 55b65f87-9102-4cb9-934a-342dd2be8e25, App ID com.ss-tpc.rd.rdcUniApp) bundled with a trojanized TikTok clone that requests photo-library access on every launch; attackers hosted the app on third-party sites that redirect iPhone users to pages mimicking the official App Store, requiring victims to manually trust the provisioning profile. On Android, the malware reached Google Play inside "SOEX," a messaging app with crypto-exchange features (10,000+ installs before takedown), and separately spreads through third-party APK distribution sites, trojanized TikTok mods, gambling/casino and adult-content apps, and LSPosed/Xposed modules that hook into app processes on rooted devices. A WebView-based scam commerce layer ("TikToki Mall") and YouTube-promoted Ponzi-style schemes further funnel victims toward malicious PWA/APK download pages.
Technically, SparkKitty masquerades its payload inside legitimate-looking components: on iOS, fake or trojanized frameworks (AFNetworking.framework, Alamofire.framework) and obfuscated dylibs (libswiftDarwin.dylib, wc.dylib, a modified libcrypto.dylib) execute via the Objective-C `+load` class method (observed entry selector `+[AFImageDownloader load]`), retrieving an AES-256 (ECB mode) encrypted configuration from an Info.plist key ("ccc") or a UserDefaults fallback ("com.tt.cf"). Execution is gated by a guardrail check: the payload validates that the Info.plist "ccool" key equals a fixed string ("77e1a4d360e17fdbc"); if the value differs, the payload does not proceed -- a config-value keying technique consistent with anti-analysis/anti-detonation design. On Android, Java/Kotlin payloads are embedded directly or injected via Xposed/LSPosed hooks into app entry-point Activities, and persist a device-identifier record at `aray/cache/devices/.DEVICES`. Both platforms compute a device identifier (MD5 of IMEI + MAC address + a random UUID on Android) and exfiltrate images via multipart form-data PUT requests to attacker C2 endpoints (`/api/putImages` on iOS, `/api/putDataInfo` on Android), preceded by heartbeat/status checks (`/api/getStatus`, `/api/getImageStatus`, `/api/anheartbeat`) that gate whether upload is permitted based on a `code`/`status` field in the JSON response. iOS traffic spoofs a TikTok User-Agent ("TikTok/31.4.0 (iPhone; iOS 14.8; Scale/3.00)") to blend in with legitimate app traffic. The Android/Kotlin module additionally probes multiple candidate C2 hosts and times each response, committing to whichever host answers fastest. C2 address lists are distributed and rotated via encrypted configuration files hosted on Aliyun OSS buckets (multiple regions: Beijing, Shenzhen, Shanghai), a Gitee repository (bbffipa/data-group), AWS S3, and UFile cloud storage -- allowing operators to update infrastructure without republishing the app binary. Independent researchers noted SparkKitty includes Frida-resistant anti-analysis checks intended to defeat dynamic instrumentation, which were subsequently bypassed via Frida hooking during analysis.
Kaspersky assesses SparkKitty as the successor/"little sibling" to SparkCat (Securelist, disclosed January 2025), the first documented OCR-based crypto-stealer trojan to reach the Apple App Store. SparkCat itself initialized through an SDK component named "Spark" (disguised as an analytics SDK, package `com.spark.stat`) registered in the Android Application subclass's `onCreate` method, downloading base64-encoded, AES-128-CBC-encrypted JSON configuration from GitLab-hosted URLs; a native Rust library (`libmodsvmp.so`) masquerading as an Android code obfuscator implemented a secondary custom TCP C2 protocol using AES-GCM-SIV encryption, ZSTD compression, and RSA key exchange, selectable via a `tfm` configuration flag alongside the primary AES-256-CBC/AES-128-CBC HTTP channel. SparkCat hijacked a legitimate third-party customer-support library (Easemob HelpDesk SDK) to request photo-gallery access under a support-chat pretext, then ran an ML Kit OCR routine that scanned images for wallet-recovery-phrase keywords and dictionary terms across nine languages (Chinese, Japanese, Korean, English, Czech, French, Italian, Polish, Portuguese), exfiltrating matches -- plus device metadata, image hashes, and recognized keywords -- to an AWS S3 bucket and a `/api/e/img/rekognition` endpoint. The two campaigns share overlapping infected Android application sets (including shared package/bundle names such as `com.websea.exchange` across both platforms), identical framework construction methodology, matching iOS debug-symbol file paths (developer paths `/Users/qiongwu/` and `/Users/quiwengjing/`), the same cryptocurrency-theft objective via OCR/ML Kit, and comparable SDK-embedding and C2-configuration patterns, though Kaspersky found insufficient evidence to attribute either campaign to a named group -- Chinese-language code strings and comments, developer-path artifacts, and regional app targeting (China, Southeast Asia) point to a Chinese-speaking, financially motivated operator rather than a nation-state actor. SparkCat was first identified when researchers statically deobfuscated the Google Play food-delivery app "ComeCome" (`com.bintiger.mall.android`, 242,000+ downloads before removal) and discovered its suspicious "Spark" SDK initialization. Following SparkKitty's disclosure, Apple removed 币coin from the App Store (2025-06-25) and Google removed SOEX from Google Play and banned the developer account; the underlying campaign, distribution infrastructure, and app-repackaging technique remain active and continue to surface in new samples and trojanized apps.
MITRE ATT&CK techniques used in TL-2026-1717
Defense Evasion
T1406 Obfuscated Files or Information; T1444 Masquerade as Legitimate Application; T1627 Execution Guardrails; T1628 Hide Artifacts
Collection
T1409 Stored Application Data; T1533 Data from Local System
Discovery
T1426 System Information Discovery
Command and Control
T1437 Application Layer Protocol; T1481 Web Service; T1521 Encrypted Channel
Initial Access
T1474 Supply Chain Compromise; T1475 Deliver Malicious App via Authorized App Store; T1476 Deliver Malicious App via Other Means; T1660 Phishing
Persistence
T1624 Event Triggered Execution
Exfiltration
Affected products and versions in SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
- Apple — App Store (iOS) -- trojanized applications including "币coin" and a fake TikTok distributed via abused enterprise provisioning profile
Vulnerable versions: Any iOS device with the trojanized app or provisioning profile installed
Fixed in: 币coin removed from the App Store 2025-06-25; no OS-level fix, mitigation is app removal / profile removal - Google — Google Play (Android) -- trojanized applications including "SOEX" (10,000+ installs)
Vulnerable versions: Any Android device with the trojanized app installed
Fixed in: SOEX removed from Google Play and developer account banned; no OS-level fix, mitigation is app removal - Various / Third-party — Sideloaded APKs and LSPosed/Xposed modules distributed via third-party sites, trojanized TikTok clones, gambling/casino, and adult-content apps
Vulnerable versions: Rooted Android devices with the malicious module or APK installed
Fixed in: N/A -- no vendor patch; requires manual removal
Remediation for SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
Immediate actions
- Uninstall 币coin, SOEX, and any trojanized TikTok clone / gambling / casino / adult-content app matching the identified hashes immediately
- Block the identified C2 IPs and domains (23.249.28.88, 23.249.28.200, 120.79.8.107, 47.119.171.161, 120.78.239.17, 39.108.186.119, 84.17.37.155, api.fxsdk.com, i.bicoin.com.cn, and associated APK-distribution domains) at DNS/network egress
- Review device photo galleries for exposed seed-phrase, recovery-phrase, or 2FA backup-code screenshots; if found, treat the associated wallet(s) as compromised and migrate funds to a newly generated wallet immediately
- On iOS, remove any untrusted enterprise/ad-hoc provisioning profiles via Settings > General > VPN & Device Management, especially any tied to certificate EHQ3N2D5WH
- On Android, uninstall any LSPosed/Xposed modules of unknown origin and check for root/hooking-framework presence on corporate-adjacent devices
Workarounds
- Restrict photo-gallery permission grants to only trusted, verified applications and revoke gallery access from any app that requests it without a clear feature need
- Avoid installing apps, configuration/provisioning profiles, or APKs from unofficial sources, scam websites, or unsolicited social-media (e.g., YouTube Ponzi-scheme) promotions
- Enable Google Play Protect scanning; treat crypto-wallet or crypto-exchange apps with unusually low install counts or recent developer accounts with added scrutiny before installing
Longer-term hardening
- Never store cryptocurrency seed phrases, private keys, or 2FA backup codes as photos or screenshots on a mobile device -- use an offline/hardware wallet or a dedicated encrypted password manager instead
- Deploy Mobile Threat Defense (MTD) / EMM tooling capable of flagging anomalous photo-gallery access combined with background network uploads
- Enforce MDM policy restricting installation of enterprise/ad-hoc provisioning profiles and sideloaded APKs on managed devices
- Maintain continuous ingestion of updated SparkKitty/SparkCat IOC feeds, since C2 infrastructure and trojanized-app hashes are rotated frequently
Timeline of SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
- Earliest observed SparkKitty samples and malicious-framework compile artifacts place the start of the campaign at least this early, per Kaspersky/Securelist analysis.
- Predecessor campaign SparkCat is independently active, distributing OCR-based crypto-stealer code via Google Play apps (including ComeCome, com.bintiger.mall.android) that accumulate 242,000+ downloads before removal.
- Kaspersky publicly documents SparkCat -- the first OCR-based crypto-seed-phrase stealer trojan found in the Apple App Store -- establishing the Google ML Kit OCR theft technique later reused by SparkKitty, and identifying its GitLab-hosted config and Easemob HelpDesk SDK abuse.
- Kaspersky/Securelist publicly discloses SparkKitty, detailing the trojanized iOS app 币coin, Android app SOEX (10,000+ installs), OCR-based and bulk gallery-image theft, and the associated C2/exfiltration infrastructure.
- Apple removes the malicious 币coin app from the App Store following Kaspersky's notification; Google separately removes SOEX from Google Play and bans the developer account.
- SparkKitty C2 domain indicators (laoqianf14/15/51.top, xinqianf38.top, and related infrastructure) are compiled and added to public IOC tracking.
- Additional SparkKitty MD5 hash indicators are identified and added to tracking, reflecting continued detection of new trojanized samples and variants.
- GBHackers and Cyberpress republish SparkKitty coverage, triggering creation of this Threadlinqs threat record via the RSS hunt pipeline.
Sources cited for SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
- SparkKitty Malware
- SparkKitty Targets iOS and Android Devices via App Store and Google Play Attacks
- SparkKitty Malware Infects iOS and Android Devices Through App Store and Google Play
- The new SparkKitty Trojan spy in the App Store and Google Play
- SparkCat crypto stealer in Google Play and App Store
- SparkKitty: a new stealer in the App Store and Google Play
- Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play
- SparkCat -- first OCR trojan stealer to infiltrate the App Store
- Malware on Google Play, Apple App Store stole your photos -- and crypto
- Saving Your Wallet Details, Seed Phrase as a Photo on Your Phone? This Trojan May Be Targeting You
- Kaspersky Warns New Crypto Malware Steals Seed Phrase Screenshots From iOS and Android
Threats related to SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors
- ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as First Gemini-Powered Android Malware
- Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan, MsDroid, MaskDroid, LAMD, ForeDroid)
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil (2025-2026)
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges
Detection coverage for TL-2026-1717
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1717 across Splunk SPL, Microsoft KQL and Sigma, covering 58 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.