Malicious iOS app FomoPeek linked to $580K crypto theft, SlowMist says
A malicious iOS app on Apple’s App Store, FomoPeek, was linked to nearly $580,000 in stolen crypto. Security researchers found it contained two hidden modules with kernel exploits that could escape Apple’s sandbox, gain elevated privileges, and access Keychain data and other apps’ files, including wallet information. SlowMist said affected versions were released on Sept. 9 and Sept. 12, while version 1.3 on Sept. 17 removed the malicious code. The exploit package reportedly included eight attack methods and claimed support for iOS 12.0 through 18.7.2 and 26.0 through 26.1. Onchain tracing identified a main hacker address that received about 579,984 USDT. The funds moved across multiple chains, were consolidated through several addresses, and some were sent to services such as FixedFloat, KuCoin, and cce.cash.
