Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
credential-stealer-activitypackage-repository-poisoningcommand-and-control-methoddata-exfiltration-method

SparkCat Stealer Reached Google Play and Apple App Store

Updated 11h agoFirst seen Feb 7, 20251 source

Researchers uncovered SparkCat, a cross-platform malware campaign that embedded malicious Android SDKs and iOS frameworks into apps distributed through both official and unofficial marketplaces, including Google Play and Apple’s App Store. The malware used Google ML Kit OCR to scan victims’ photo galleries for cryptocurrency wallet recovery phrases, then selectively exfiltrated matching images to attacker-controlled infrastructure. Infected Android apps on Google Play were downloaded more than 242,000 times, and researchers described the iOS findings as the first known case of a stealer discovered in Apple’s App Store.

SparkCat appears to have been active since at least March 2024 and targeted users across Europe and Asia using multilingual keyword lists and localized dictionaries to identify seed phrases. The campaign also used obfuscation and a Rust-based custom C2 protocol to hinder analysis and manage communications. Following disclosure, Apple removed the malicious iOS apps on 2025-02-06, and Google removed the malicious Android apps on 2025-02-07.

Share:
SparkCat Stealer Reached Google Play and Apple App Store
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 7, 20251y ago

Google removes malicious SparkCat Android apps from Google Play

Google removed the malicious Android applications associated with SparkCat from Google Play. The infected apps identified in Google Play had accumulated more than 242,000 downloads.

SparkCat crypto stealer in Google Play and App Store | Securelist
Feb 6, 20251y ago

Apple removes malicious iOS apps from the App Store

Apple removed the malicious iOS applications linked to SparkCat from the App Store. Researchers described the operation as the first known case of a stealer discovered in Apple’s App Store.

SparkCat crypto stealer in Google Play and App Store | Securelist
Feb 5, 20251y ago

SparkCat campaign begins targeting Android and iOS users

Researchers said the SparkCat malware campaign appears to have been active since at least March 2024. The campaign embedded malicious Android SDKs and iOS frameworks into apps distributed through official and unofficial app stores.

SparkCat crypto stealer in Google Play and App Store | Securelist
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
Amazon Simple Storage ServiceGitlab
Organizations
7 linked
AppleGoogleComeComeAmazon Web ServicesGitLabEsetEasemob
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.