Crypto
Home›Crypto›Regulation›Malicious iOS FomoPeek app tied to nearly $580,000 in…
Malicious iOS FomoPeek app tied to nearly $580,000 in crypto theft
SlowMist said FomoPeek versions released Sept. 9 and Sept. 12 carried kernel exploits, while version 1.3 released Sept. 17 removed the malicious components.
Blockchain security firm SlowMist said a malicious iOS app distributed through Apple’s App Store, called FomoPeek, was linked to nearly $580,000 in stolen crypto.
In an investigation with the OKX security team, SlowMist said the app contained multiple kernel exploits designed to escape Apple’s sandbox and access sensitive wallet data, including Keychain data and files belonging to other apps.
SlowMist said affected versions were released on Sept. 9 and Sept. 12, while version 1.3 released Sept. 17 removed the malicious components, and it estimated the exploit framework targeted iOS versions spanning 12.0 to 18.7.2 and 26.0 to 26.1.
The firm said its researchers found the app’s framework loaded when FomoPeek launched, with a remote server able to control exploitation and data collection, and it named wallet and note app targets including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes.