logo

BombFlower Backdoor: Uncovering an Evasive Fake Wallet Campaign

ID: 771a5a0d-fa07-5c53-b750-7636d4fbebce

STIX ID: report--771a5a0d-fa07-5c53-b750-7636d4fbebce

Feed Name: CertiK Blog

Threat Score
75/100

Date Published: 2023-01-19

Date Updated: 2026-06-11

...
...

CertiK reports on the BombFlower campaign, an organized criminal group deploying trojanized Android wallet apps that conceal and install an embedded malicious APK which hooks wallet mnemonic generation to exfiltrate users' private keys. The group employs advanced evasion (embedded ZipBomb anti-forensics), SEO manipulation, and distributed cloud hosting to avoid detection and maximize victim reach; network captures and timeline analysis demonstrate active exploitation and infrastructure commonalities across samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.