Malicious iOS App FomoPeek Linked to Theft of Nearly $580,000 in Cryptocurrency Assets
The malicious iOS app FomoPeek was found to contain multiple kernel exploit modules that can break out of Apple’s sandbox and access sensitive wallet data from other apps. It has been linked to an incident in which nearly $580,000 in cryptocurrency assets were stolen. Blockchain security firm SlowMist said the app was distributed via Apple’s App Store. The company stated that the affected versions were released on September 9 and September 12. The app includes two malicious modules that can obtain higher privileges and access other apps’ Keychain data and files. The 1.3 version released on September 17 removed the related malicious components. SlowMist and the OKX security team found that the associated attack framework includes eight attack methods, supporting iOS 12 through 18.7.2 and versions 26 through 26.1. On-chain analysis shows that a hacker address associated with the incident received about 580,000 USDT; the funds were then transferred through multiple addresses and services, with some going to FixedFloat, KuCoin, and cce.cash.