Malicious iOS App FomoPeek Linked to $580K Crypto Theft, SlowMist Reports

Kernel exploits used to escape sandbox and access wallet data on Apple's App Store

By LineZotpaper
Published
Read Time2 min
Blockchain security firm SlowMist has linked a malicious iOS application called FomoPeek, distributed through Apple's official App Store, to the theft of nearly $580,000 in cryptocurrency. According to SlowMist's investigation, the app contained iOS kernel exploits that allowed it to escape Apple's sandbox and access sensitive data from other applications, including cryptocurrency wallet information.

The investigation, published by SlowMist, reveals that FomoPeek introduced two malicious modules capable of exploiting iOS vulnerabilities. These modules enabled the app to gain elevated privileges and access Keychain data as well as files belonging to other apps on the device. The exploits allowed the malware to bypass Apple's security sandbox, a core protection that normally restricts what one app can access on another app's data.

The app was available on the official App Store, raising concerns about the effectiveness of Apple's review process. Users who downloaded FomoPeek and also had cryptocurrency wallets on their devices were at risk. The reported theft of approximately $580,000 underscores the financial impact of the malware.

SlowMist's findings highlight the sophistication of the attack, which combined social engineering (the app's presence on the App Store) with advanced kernel-level exploitation. The security firm's threat intelligence analysis details how the malicious modules were designed to evade detection and extract sensitive information from targeted devices.

§

Analysis

Why This Matters

  • Cryptocurrency users on iOS face direct financial risk if malicious apps bypass Apple's security layers.
  • The App Store's trustworthiness is challenged by a malware sample that used kernel exploits to steal wallet data.
  • This incident may prompt tighter app review processes and increased awareness among users about wallet security on mobile devices.

Background

Apple's iOS is widely regarded as a secure mobile operating system, partly due to its sandboxing and strict app review process. However, sophisticated attackers have previously found ways to distribute malicious apps, often using social engineering or exploiting zero-day vulnerabilities. Cryptocurrency wallets are high-value targets, and mobile malware designed to steal private keys or seed phrases has become a growing concern in the crypto community.

Key Perspectives

Crypto users and security researchers: The breach demonstrates that even official app stores are not immune to advanced malware. Users are advised to scrutinize app permissions and consider using hardware wallets or dedicated secure devices for crypto storage. Apple's App Store security team: While no official statement has been reported, the incident puts pressure on Apple to investigate the review process that allowed FomoPeek to be listed and to address the underlying kernel vulnerabilities exploited. SlowMist and blockchain security firms: Their analysis serves as a warning to the industry, highlighting the need for continuous monitoring of app store ecosystems and proactive sharing of threat intelligence.

What to Watch

  • Any official response or action from Apple regarding FomoPeek and App Store security.
  • Reports of additional victims or similar malware samples exploiting the same vulnerabilities.
  • Updates from SlowMist or other researchers on the specific kernel exploits used and whether they have been patched in recent iOS updates.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.