📅 Thursday, 10 September 2026 · --:-- UTC Follow us
Ecosystem
ID EN
Malware SparkKitty Tembus Filter Apple dan Google Play - Modusnya Mengincar Galeri Foto

SparkKitty Malware Bypasses Apple and Google Play Filters - Targets Photo Galleries

Apple and Google’s app store defenses have been breached. A malware strain known as SparkKitty successfully infiltrated the Apple App Store and Google Play, while also spreading via third-party app stores to widen its attack vector. The malicious program was first detected by Kaspersky in June 2025. Now, Check Point has released an in-depth analysis detailing how SparkKitty operates to steal victims’ assets.

Why Photo Galleries Are the Target

Most malicious software relies on keyloggers to record password keystrokes or monitor clipboards when users copy text. SparkKitty takes a completely different route. The malware was intentionally designed not to record keyboard activity. Once installed, SparkKitty quietly scans the victim’s entire smartphone photo gallery.

Its goal is singular: searching for screenshots containing crypto wallet seed phrases. All scanned visual data is then transmitted directly to an attacker-controlled server.

In the iOS ecosystem, SparkKitty hid behind a crypto app called “币coin”. The app slipped past Apple’s strict review process. Only after users downloaded and opened it did the app start requesting full access permissions to their private photo galleries.

Meanwhile on Android devices, the program disguised itself as a messaging and crypto exchange app named SOEX. This camouflage lasted long enough for SOEX to be downloaded more than 10,000 times before it was finally removed from the Google Play catalog. Other SparkKitty variants were also caught spreading through fake TikTok apps, online gambling platforms, and sideloaded APK files installed from outside official ecosystems.

Threats Spill into the Physical World

Beyond software hacking, the digital asset theft trend has also expanded into physical violence. Recent research from security firm CertiK documented at least 52 incidents of theft involving direct physical violence or “wrench attacks” during the first half of 2026. Financial losses from these street-level crimes jumped nearly 12-fold year-over-year, surpassing $124 million.

Elsewhere in cyberspace, hacker tactics for distributing malware are also expanding. Alongside the spread of SparkKitty, Kaspersky reported a new trend where attackers leverage the Steam Workshop platform to plant malicious software onto user devices.

These recent incidents highlight one critical takeaway: secure your assets using the most fundamental methods. Write your wallet seed phrase offline on paper or store it on a metal plate, and make sure to download apps only from trusted developers. Promptly restrict permissions for any app requesting photo gallery access without a compelling reason. Never store recovery phrases as screenshots, as those image files could be transferred to a hacker’s server before you even realize it.

Reported by Decrypt.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
📩 KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share