The investigation, published by SlowMist, reveals that FomoPeek introduced two malicious modules capable of exploiting iOS vulnerabilities. These modules enabled the app to gain elevated privileges and access Keychain data as well as files belonging to other apps on the device. The exploits allowed the malware to bypass Apple's security sandbox, a core protection that normally restricts what one app can access on another app's data.
The app was available on the official App Store, raising concerns about the effectiveness of Apple's review process. Users who downloaded FomoPeek and also had cryptocurrency wallets on their devices were at risk. The reported theft of approximately $580,000 underscores the financial impact of the malware.
SlowMist's findings highlight the sophistication of the attack, which combined social engineering (the app's presence on the App Store) with advanced kernel-level exploitation. The security firm's threat intelligence analysis details how the malicious modules were designed to evade detection and extract sensitive information from targeted devices.