SparkCat malware returns to target Android and iOS users, hiding in innocent apps to try and steal your details
- SparkCat infostealer hidden in iOS App Store and Play Store apps
- Targets cryptocurrency seed phrases via OCR and keywords
- New obfuscation techniques make detection more difficult
SparkCat, a mobile-first infostealer that targets people’s cryptocurrencies, is back with new upgrades that make it more difficult to spot.
Cybersecurity researchers Kaspersky claim to have found multiple apps both in the Apple App Store and the Google Play Store delivering the malware.
Apple and Google app repositories are generally safe, and knowing the size and the popularity of the platforms, both companies go the extra mile to make sure the apps offered there are clean. However, every once in a while, threat actors manage to work around the perimeter to smuggle malicious apps inside.
Article continues below
Hunting for mnemonics
In this case, Kaspersky said it discovered enterprise messengers and food delivery services apps hiding SparkCat.
This infostealer was first spotted in 2025, hunting for people’s mnemonic seeds, or “seed phrases” – a set of 12 or 24 seemingly random words which can be used to load a person’s cryptocurrency wallet on another device as a backup solution in case the device is lost or broken.
SparkCat recently made headlines for the way it used OCR (Optical Character Recognition) to extract seed phrases from photos and screenshots. It targeted primarily Asian users and, while the new version still does the same, it has taken a step further to potentially target Western users, as well.
The Android version still hunts for Japanese, Korean, and Chinese keywords. The iOS version, however, hunts for English mnemonics.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Kaspersky also says that some changes were made under the hood as well, with the developers adding code virtualization and cross-platform languages for better obfuscation. These techniques, they claim, are rarely seen in mobile malware.
The researchers said they reported their findings to both Google and Apple, and that “some” of the malicious apps were already removed.
Via The Hacker News

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
SparkCat infostealer hidden in iOS App Store and Play Store apps Targets cryptocurrency seed phrases via OCR and keywords New obfuscation techniques make detection more difficult SparkCat, a mobile-first infostealer that targets people’s cryptocurrencies, is back with new upgrades that make it more difficult to spot. Cybersecurity researchers Kaspersky claim…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023