SparkKitty, a cross-platform malware family targeting cryptocurrency users, has been distributed through Apple's App Store, Google Play and third-party Android app stores, according to Check Point, which detailed the malware in a report published Sunday.

The malware searches images stored on infected devices for cryptocurrency wallet recovery phrases using optical character recognition (OCR), allowing attackers to extract sensitive credentials without relying on keystroke logging or clipboard monitoring.

Check Point said SparkKitty appears to be an evolution of SparkCat, an OCR-based stealer that Kaspersky documented in 2025 and that also pulled data from screenshots.

The security firm noted that SparkKitty spreads through trojanized applications masquerading as cryptocurrency services, messaging platforms and entertainment apps.

Once installed, the applications request permission to access a user's photo library before continuously scanning existing and newly added images.