Apple and Android users told to delete these fake apps to avoid malicious trojan

Apple and Android users are being warned about dangerous fake apps being used to spread new malware called SparkKitty, which steals personal details.

Apple and Android users told to delete these fake apps to avoid malicious trojan

(Image: PA)

Apple and Android users are being warned about dangerous fake apps being used to spread a malicious virus onto unsuspecting devices.

New malware known as SparkKitty has been discovered by researchers at Kaspersky on both Android and iOS devices.

The malware steals sensitive information by scanning images on infected phones.

AI-based Attacks are Targeting and Succeeding on Mobile

The sophistication and volume of mobile threats expected five years from now are already here.

Learn more in Zimperium’s 2026 Global Mobile Threat Report: https://t.co/kExDZJz38f pic.twitter.com/UQTnfAfz0X— Zimperium (@Zimperium) July 29, 2026

The fake Apple and Android apps to avoid

SparkKitty was found hidden inside trojanized apps listed on the Apple App Store and Google Play Store, including one called “币coin” on iOS, according to Check Point Exposure Management.

The app bypassed Apple’s security checks by embedding its malicious code in legitimate-looking frameworks.

On Android devices, SparkKitty was distributed through an app named “SOEX,” which was downloaded more than 10,000 times before it was removed from the Google Play Store.

Posing as a messaging and cryptocurrency exchange tool, the app covertly accessed media files, monitored directories, and uploaded extracted information to a remote server.

Additional variants of the malware were spread through third-party stores, sideloaded APKs (Android Package Kits), and modified versions of popular apps, including TikTok clones and gambling platforms.

Once installed, SparkKitty requested access to the device’s photo gallery.

If permission was granted, it regularly scanned images for readable text, with a particular focus on screenshots likely to contain financial data, passwords, or QR codes.

Any extracted information, along with device metadata, was then uploaded to the attacker’s infrastructure.

The malware also used advanced persistence mechanisms.

On rooted Android devices, it employed Xposed framework modules to maintain long-term control and avoid detection.

Users are advised to exercise caution when downloading apps, even from official stores.

Have you downloaded any of these fake apps? Let us know in the poll above or in the comments below.