Malicious iOS application FomoPeek linked to nearly $580,000 in cryptocurrency theft
Malicious iOS application FomoPeek has been found to contain multiple kernel exploit modules that can bypass Apple's sandbox and access sensitive wallet data from other applications, and is linked to a theft incident involving nearly $580,000 in cryptocurrency assets. Blockchain security company SlowMist stated that the application is distributed through the Apple App Store. The company noted that the affected versions were released on September 9 and September 12, and the application contains two malicious modules that can gain higher privileges and access Keychain data and files from other applications.
Version 1.3, released on September 17, has removed the related malicious components. SlowMist and the OKX security team investigated and found that the related attack framework includes 8 types of attack methods, supporting iOS versions 12 to 18.7.2 and 26 to 26.1. On-chain analysis shows that a hacker address related to the incident received approximately 580,000 USDT, and the funds were subsequently transferred through multiple addresses and services, with some flowing to FixedFloat, KuCoin, and cce.cash.






