logo

Sophisticated SeaFlower Backdoor Campaign Targets Web3 Wallets to Steal Seed Phrases

ID: f6a9ee76-0a58-58f3-97d7-2e2277114edb

STIX ID: report--f6a9ee76-0a58-58f3-97d7-2e2277114edb

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SeaFlower (藏海花) is a highly sophisticated campaign that installs pixel-perfect, backdoored clones of major Web3 wallets (Coinbase Wallet, MetaMask, TokenPocket, imToken) on iOS and Android via cloned websites and provisioning profile abuse; injected dynamic libraries and smali code intercept seed phrases and exfiltrate wallet data to attacker-controlled domains, enabling direct theft of cryptocurrency. Analysis includes technical TTPs, SHA-256 hashes and domains as IOCs, and attribution signals linking the campaign to Chinese-speaking operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.