Researchers from SlowMist have reported multiple incidents of asset theft among users of the iOS version of the FomoPeek app. Their investigation uncovered malicious code that intercepted seed phrases from cryptocurrency wallets.
Source: X/SlowMist.Experts noted that all confirmed cases involved the leakage of private keys. Many of the affected users had previously installed and used versions 1.1 and 1.2 of FomoPeek.
Devices running iOS versions 12.0-18.7 and 26.0-26.1 are at risk.
These versions contained two unauthorized modules unrelated to the app's stated functions. One of these modules incorporates DarkSword frameworks for exploiting the iOS kernel, featuring eight attack methods and the capability to automatically select the appropriate option based on the device model and OS version.
If successfully implemented, the app could escape the sandbox, access Keychain data, decrypt it, and read files from other applications on the device.
Researchers also indicated that the app connects to hidden servers not associated with the official FomoPeek services and can receive remote commands.
According to SlowMist, the malicious functionality is already activated and runs automatically at regular intervals. Devices using older iOS versions are considered more vulnerable.
FomoPeek users have been advised to monitor their accounts for suspicious activity, create a new account with a new seed phrase and private key on a trusted device, and transfer their assets as soon as possible.
Furthermore, SlowMist recommended updating iOS to the latest available version, refraining from reinstalling the app, and contacting official support if any signs of compromise are detected, while retaining the device and related materials for investigation.
It is worth noting that back in April, scammers stole $9.5 million through a phishing app posing as Ledger in the App Store.
