Suspicious SparkKitty Photo Exfiltration API Pattern

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

What it detects

This rule detects network requests to the SparkKitty spyware image-collection API paths such as getImageStatus putImages and putDataInfo used to upload stolen photos from infected mobile devices. This Trojan spy embedded in App Store and Google Play apps harvests gallery images that may contain wallet seed phrases. The structured API endpoint set is a distinctive server-side indicator.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.