
A new strain of Android malware, dubbed SparkKitty, has been detected lurking in official and third-party app stores, specifically engineered to steal cryptocurrency wallet seed phrases. Researchers uncovered the malicious code embedded in seemingly legitimate applications, including utility tools and lifestyle apps.
Once installed, SparkKitty waits for users to copy or type their 12- or 24-word recovery seeds into any app—including official crypto wallets. It then intercepts the clipboard data or keystrokes and exfiltrates it to a remote server controlled by attackers.
The malware employs a technique known as clipboard hijacking, which has grown more common among crypto-targeting threats. When a user copies their seed phrase, SparkKitty replaces it with a fraudulent address or simply sends the original data to the attacker.
Security analysts note that the malware also has keylogging capabilities, allowing it to capture seeds typed directly into wallet apps. The stolen phrases give attackers full control over victims' wallets, enabling them to drain funds without any further authentication.
SparkKitty was found on Google Play disguised as a QR code scanner and a battery saver app. It also spread through third-party Android stores popular in India and Southeast Asia, where users often sideload apps.
Google has removed the identified malicious apps from its store, but copies may still be available elsewhere. The malware uses obfuscation techniques to evade detection during initial review, only activating its payload after installation.
Experts recommend that users never store seed phrases digitally—whether in notes, screenshots, or cloud services. Hardware wallets and offline backups remain the safest options.
Users should also review app permissions carefully. Any app requesting access to clipboard or keyboard input without a clear reason should be treated with suspicion. Installing only trusted, well-reviewed apps from official sources reduces risk but does not eliminate it entirely.
Antivirus tools that scan for malware behavior can help, but the best defense is keeping seed phrases offline and never typing them into any device connected to the internet.
Security researchers are monitoring for updated variants of SparkKitty that may use more advanced evasion tactics. Users should stay alert for unexpected clipboard changes or apps that ask for unnecessary permissions.
As crypto adoption grows in India, such targeted malware is likely to become more prevalent. Wallet developers are also working on built-in protections, but the onus remains on users to safeguard their recovery seeds.