Attack Dissection: The "Invisible" Evolution from SparkCat to SparkKitty
On June 23, 2025, Kaspersky's Threat Research Team first disclosed SparkKitty, describing it as a "highly covert image-stealing malware." This virus shares a common origin with the SparkCat malware discovered in early 2024, sharing similar code structures and attack methods, but with more advanced techniques. Kaspersky analysts pointed out that SparkKitty's earliest activities can be traced back to February 2024, initially targeting Southeast Asia and China, infiltrating user devices by disguising itself as cryptocurrency, gambling, and communication applications.
The core objective of SparkKitty is to steal all the pictures in the photo album, with a focus on screenshots of cryptocurrency wallet seed phrases. Seed phrases are the only way to recover a crypto wallet.