Malicious iOS App FomoPeek Linked to $579K Crypto Theft
Security researchers at blockchain security firm SlowMist have identified a malicious iOS app called FomoPeek that was distributed through Apple's App Store. The app contained kernel exploitation capabilities designed to break out of Apple's sandbox and reach sensitive wallet-related data.
The investigation, which began after users reported experiencing crypto theft, found that the app included multiple attack modules capable of elevating privileges and stealing data stored by other apps, including items accessible via iOS Keychain mechanisms. The malicious components were distributed in specific app versions released on September 9 and 12, and removed in version 1.3 released on September 17.
The researchers tied the on-chain activity to a primary hacker address that received approximately $579,984 USDT, which was later routed across several services and networks. The exploit framework used by FomoPeek claimed support for a wide range of iOS versions, specifically 12.0 to 18.7.2 and 26.0 to 26.1.