“FakeWallet” Trojan Masquerades as Crypto Wallets to Drain Assets
ID: 46d10a2a-252f-5c5c-b4ba-1fd2c1c2e8f1
STIX ID: report--46d10a2a-252f-5c5c-b4ba-1fd2c1c2e8f1
Feed Name: securityonline.info
Threat Score
Kaspersky discovered a campaign of more than twenty typosquatting and trojanized crypto wallet apps on the Apple App Store (active since fall 2025) that use stub apps, library injection and enterprise provisioning profile abuse to steal recovery phrases and private keys from hot and cold wallet users, primarily targeting China.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
