Sophisticated SeaFlower Backdoor Campaign Targets Web3 Wallets to Steal Seed Phrases
ID: f6a9ee76-0a58-58f3-97d7-2e2277114edb
STIX ID: report--f6a9ee76-0a58-58f3-97d7-2e2277114edb
Feed Name: cybersecurityNews.com
SeaFlower (藏海花) is a highly sophisticated campaign that installs pixel-perfect, backdoored clones of major Web3 wallets (Coinbase Wallet, MetaMask, TokenPocket, imToken) on iOS and Android via cloned websites and provisioning profile abuse; injected dynamic libraries and smali code intercept seed phrases and exfiltrate wallet data to attacker-controlled domains, enabling direct theft of cryptocurrency. Analysis includes technical TTPs, SHA-256 hashes and domains as IOCs, and attribution signals linking the campaign to Chinese-speaking operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
