{"id":77954,"date":"2025-06-25T09:59:56","date_gmt":"2025-06-25T06:59:56","guid":{"rendered":"https:\/\/gulftech-news.com\/en\/?p=77954"},"modified":"2025-06-25T09:59:57","modified_gmt":"2025-06-25T06:59:57","slug":"kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play","status":"publish","type":"post","link":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/","title":{"rendered":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play"},"content":{"rendered":"\n<p><strong><a href=\"https:\/\/me.kaspersky.com\/\">Kaspersky <\/a><\/strong>researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information about the device to the attackers. This malware was embedded in apps related to crypto and gambling, as well as in a trojanized TikTok app, and was distributed on App Store and Google Play, as well as on scam websites. <\/p>\n\n\n\n<p>Experts suggest that the goal of the attackers is to steal cryptocurrency assets from residents of Southeast Asia and China. Users in KSA are also potentially at risk of facing a similar cyber threat.<\/p>\n\n\n\n<p>Kaspersky has notified Google and Apple about the malicious apps. Certain technical details suggest that the new malware campaign is linked to the previously discovered <a href=\"https:\/\/securelist.com\/sparkcat-stealer-in-app-store-and-google-play\/115385\/\">SparkCat<\/a> Trojan \u2014 malware (the first of its kind on iOS) with a built-in optical character recognition (OCR) module that allows it to scan image galleries and steal screenshots containing cryptocurrency wallet recovery phrases or passwords. <\/p>\n\n\n\n<p>The SparkKitty case is the second time in a year that Kaspersky researchers have found a Trojan stealer on App Store, following SparkCat.<\/p>\n\n\n\n<p><strong>iOS<\/strong><\/p>\n\n\n\n<p>On App Store, the Trojan pretended to be an app related to cryptocurrencies \u2014 \u5e01coin.&nbsp;On phishing pages mimicking the official iPhone App Store, the malware was distributed under the guise of TikTok and gambling applications.<\/p>\n\n\n\n<p><em>An alleged crypto exchange app, <\/em>\u5e01<em>coin<\/em>,<em> on App Store<\/em><\/p>\n\n\n\n<p><em>A webpage mimicking AppStore to install an alleged TikTok app through developer tools<br><br><\/em><\/p>\n\n\n\n<p><em>A fake web store embedded into the alleged TikTok app<\/em><\/p>\n\n\n\n<p>&#8220;One of the vectors for the Trojan&#8217;s distribution turned out to be fake websites where the attackers tried to infect the victims&#8217; iPhones. iOS has several legitimate ways to install programs not from the App Store. In this malicious campaign, the attackers used one of them \u2014 special developer tools for distributing corporate business applications. <\/p>\n\n\n\n<p>In the infected version of TikTok, during authorization, the malware, in addition to stealing photos from the smartphone gallery, embedded links to a suspicious store in the person&#8217;s profile window. This store only accepts cryptocurrencies, which increases our concerns about it,\u201d explains Sergey Puzan, a malware expert at Kaspersky.<\/p>\n\n\n\n<p><strong>Android<\/strong><\/p>\n\n\n\n<p>The attackers targeted users both on third-party websites and on Google Play, passing off the malware as various crypto services. For example, one of the infected applications \u2014 a messenger called SOEX with a cryptocurrency exchange function \u2014 was downloaded from the official store over 10,000 times.&nbsp;<\/p>\n\n\n\n<p><em>An alleged crypto exchange app, SOEX, on Google Play<\/em><\/p>\n\n\n\n<p>Experts also found APK files of infected apps (these can be installed directly on Android smartphones bypassing official stores) on third-party websites that are likely related to the detected malicious campaign. They are positioned as investment crypto projects. The websites on which these applications were posted were advertised on social networks, including YouTube.&nbsp;<\/p>\n\n\n\n<p>&#8220;After the apps were installed, they functioned as promised in their description. But at the same time, photos from the smartphone gallery were sent to the attackers. The attackers may later try to find various confidential data in the images, for instance, crypto wallet recovery phrases to access the victims&#8217; assets. There are indirect signs that the attackers are interested in people&#8217;s digital assets: many of the infected apps were related to crypto, and the trojanized TikTok app also had a built-in store that accepted payment for goods only in crypto,&#8221; comments Dmitry Kalinin, a malware expert at Kaspersky.&nbsp;<\/p>\n\n\n\n<p>A detailed report about this attack is available on <a href=\"https:\/\/securelist.com\/sparkkitty-ios-android-malware\/116793\/\">Securelist.com<\/a>.&nbsp;<\/p>\n\n\n\n<p>To avoid becoming a victim of this malware, Kaspersky recommends the following safety measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If you have installed one of the infected applications, remove it from your device and do not use it until an update has been released to eliminate the malicious functionality.<\/li>\n\n\n\n<li>Avoid storing screenshots containing sensitive information in your gallery, including cryptocurrency wallet recovery phrases. Passwords, for example, could be stored in specialized applications such as\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r06\/___https:\/www.kaspersky.com\/ufxxBtwi-rfsfljw___.ZXV3MjpuZXh0MTU6YzpvOjUyZjU1M2UxM2MxNDRhNThlOWQ0ZDg0ZThiZWRhOGQ0Ojc6MzRhNzpkZTE4MzhkMzY5NGU1OTkyZjYxYTRlODkyOTlhMjg2OTU4MWNlMDM2OWI5NWM5MmYzNDAwN2M2YTgzN2RkOWM4OnA6RjpU\">Kaspersky Password Manager<\/a>.<\/li>\n\n\n\n<li>Reliable cybersecurity software, like\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r06\/___https:\/www.kaspersky.com\/uwjrnzr___.ZXV3MjpuZXh0MTU6YzpvOjYwZThhMjc3N2UyZjk5M2ZhNDM0ZmRiMGFmNjhkMjE1Ojc6ODIzZDo2MTMxZTljNDRkMGM3ZDRmMjg5ZWZkYmM4YzQ5YTU2NTUzNDZhMTEzNjdjY2NhNWFiYTQ2ZTYwYTc4YzE3YWZkOnA6RjpU\">Kaspersky Premium<\/a>, can prevent malware infections. Due to the architectural features of the Apple operating system, the Kaspersky solution for iOS shows the user a warning if it detects an attempt to transfer data to the attacker&#8217;s command server, and blocks the attacker from transferring data.<\/li>\n<\/ul>\n\n\n\n<p>If an app asks for permission to access the phone&#8217;s photo library, consider if this app really needs it.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information about the device to the attackers. This malware was embedded in apps related to crypto and gambling, as well as in a trojanized TikTok app, and was distributed on &hellip;<\/p>\n","protected":false},"author":2,"featured_media":77956,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[644],"tags":[2971,2972,1088,2970],"class_list":["post-77954","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-communications-technology","tag-app-store","tag-google-play","tag-kaspersky-4","tag-sparkkitty"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News\" \/>\n<meta property=\"og:description\" content=\"Kaspersky researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information about the device to the attackers. This malware was embedded in apps related to crypto and gambling, as well as in a trojanized TikTok app, and was distributed on &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/\" \/>\n<meta property=\"og:site_name\" content=\"Gulf Tech News\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-25T06:59:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-25T06:59:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789\" \/>\n\t<meta property=\"og:image:width\" content=\"780\" \/>\n\t<meta property=\"og:image:height\" content=\"405\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"bessan helmi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"bessan helmi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/\",\"url\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/\",\"name\":\"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News\",\"isPartOf\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789\",\"datePublished\":\"2025-06-25T06:59:56+00:00\",\"dateModified\":\"2025-06-25T06:59:57+00:00\",\"author\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\"},\"breadcrumb\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage\",\"url\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789\",\"contentUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789\",\"width\":780,\"height\":405,\"caption\":\"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gulftech-news.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\",\"url\":\"https:\/\/gulftech-news.com\/en\/\",\"name\":\"Gulf Tech News\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gulftech-news.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\",\"name\":\"bessan helmi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"caption\":\"bessan helmi\"},\"url\":\"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/","og_locale":"en_US","og_type":"article","og_title":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News","og_description":"Kaspersky researchers have discovered a new Trojan spy called SparkKitty which targets smartphones on iOS and Android. It sends images from an infected phone and information about the device to the attackers. This malware was embedded in apps related to crypto and gambling, as well as in a trojanized TikTok app, and was distributed on &hellip;","og_url":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/","og_site_name":"Gulf Tech News","article_published_time":"2025-06-25T06:59:56+00:00","article_modified_time":"2025-06-25T06:59:57+00:00","og_image":[{"width":780,"height":405,"url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789","type":"image\/png"}],"author":"bessan helmi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"bessan helmi","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/","url":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/","name":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play - Gulf Tech News","isPartOf":{"@id":"https:\/\/gulftech-news.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage"},"image":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage"},"thumbnailUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789","datePublished":"2025-06-25T06:59:56+00:00","dateModified":"2025-06-25T06:59:57+00:00","author":{"@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c"},"breadcrumb":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#primaryimage","url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789","contentUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/06\/Kaspersky-New-Logo-2.png?v=1750834789","width":780,"height":405,"caption":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play"},{"@type":"BreadcrumbList","@id":"https:\/\/gulftech-news.com\/en\/2025\/06\/25\/kaspersky-has-discovered-sparkkitty-a-new-trojan-spy-on-app-store-and-google-play\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gulftech-news.com\/en\/"},{"@type":"ListItem","position":2,"name":"Kaspersky has discovered SparkKitty: a new Trojan spy on App Store and Google Play"}]},{"@type":"WebSite","@id":"https:\/\/gulftech-news.com\/en\/#website","url":"https:\/\/gulftech-news.com\/en\/","name":"Gulf Tech News","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gulftech-news.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c","name":"bessan helmi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","caption":"bessan helmi"},"url":"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/"}]}},"_links":{"self":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77954","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/comments?post=77954"}],"version-history":[{"count":1,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77954\/revisions"}],"predecessor-version":[{"id":77957,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/77954\/revisions\/77957"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media\/77956"}],"wp:attachment":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media?parent=77954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/categories?post=77954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/tags?post=77954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}