SlowMist Warns FomoPeek iOS Exploit Could Steal Crypto Private Keys

Paxful
Bybit


SlowMist warns FomoPeek versions 1.1–1.2 contain malicious code that could expose private keys, seed phrases, credentials, and files.

SlowMist has warned crypto users about malicious FomoPeek app versions 1.1–1.2. The security company has connected these versions with several reports of stolen user assets.

FomoPeek App Contains Advanced iOS Exploit Framework

SlowMist has conducted an investigation with the OKX security team for the reported cases. Their research revealed malicious code in FomoPeek 1.1 – 1.2.

SlowMist says the app has 2 modules that are not related to its business functions. The first module has an iOS kernel exploitation framework that includes 8 different exploit methods.

bybit

Related reading: North Korean Hackers Infect 30,000 Devices, Target 7,000 Crypto Wallets | Live Bitcoin News

In addition, the framework can automatically choose an attack approach. It depends on the model of the device and the version of iOS installed on it.

The investigation revealed that it is possible to affect versions ranging from iOS 12.0 to 18.7. It also noted that iOS versions 26.0 to 26.1 are affected.

The exploit, if it works, can reportedly bypass the iOS application sandbox. Consequently, it can reach protected areas that ordinary applications cannot access.

SlowMist claims the exploit has access to and decryption capabilities for Keychain. It can also read other files from other applications installed on the device.

This means that sensitive data might be exposed. This information comprises private keys, seed phrases, login credentials, chat histories, and personal files.

Private keys can provide direct control over crypto wallets. Meanwhile, seed phrases can be used to recover wallets and access the blockchain assets linked to them.

The investigation also revealed that the application had hidden server connections. These servers are said to be not related to FomoPeek’s public-facing services.

Furthermore, the concealed servers are able to obtain and send remote commands. SlowMist also studied the unencrypted network traffic in its investigation.

The security company stated that the malicious features are still active. It is said to operate automatically at regular intervals, without the need for repeated user actions.

Investigation Links FomoPeek Versions to Asset Theft Reports

SlowMist reports that it has heard of several instances of asset theft. In these cases, the investigation revealed that private keys had been exposed.

Some of the users had previously installed and used FomoPeek versions 1.1–1.2. This relationship led to the joint investigation by SlowMist and OKX security teams.

The results show that the malicious modules are not part of the stated functions of FomoPeek. Their skills, on the other hand, offer access to sensitive information throughout the device.

SlowMist suggests that older versions of iOS could be more vulnerable. The investigation also uncovered affected devices running newer versions, however.

The case illustrates how malicious applications can be built to incorporate both software functionality and sophisticated exploitation techniques. In addition to attacking blockchain networks, attackers can gain access to devices that contain wallet information.

In the meantime, the kernel framework’s capacity to pick various exploit approaches adds to its versatility. The framework reportedly adapts its approach according to the targeted device and iOS version.

The incident also highlights the dangers that cryptocurrency users are exposed to outside of wallet applications. Malicious software can gain deeper access to the device and thus compromise sensitive wallet credentials.

SlowMist’s investigation continues to be limited to the reported FomoPeek versions. So, users need to be aware of these results and differentiate them from other iOS exploit chain claims.



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*