FomoPeek Malware Exploits iOS Vulnerabilities for Crypto Heist
A malicious iOS app distributed through Apple's App Store has been linked to nearly $580,000 in stolen cryptocurrency. The app, called FomoPeek, introduced two malicious modules that could exploit iOS vulnerabilities and access sensitive wallet data.
According to an investigation published by blockchain security firm SlowMist, the affected versions of the app were released on September 9 and 12. However, version 1.3, released on September 17, removed the malicious components.
The exploit framework included eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. SlowMist's onchain analysis identified a primary hacker address associated with the incident that received about 579,984 USDT.
The stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services. Portions of the funds were transferred toward services including FixedFloat, KuCoin, and cce.cash, while other funds were dispersed through additional addresses that SlowMist continued to trace.