logo

FakeWallet crypto stealer spreading through iOS apps in the App Store

ID: 70fb418f-e806-54a3-a205-734a5a46d3d0

STIX ID: report--70fb418f-e806-54a3-a205-734a5a46d3d0

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-29

Author: Sergey Puzan

...
...

In March 2026 researchers uncovered a campaign (FakeWallet) that published over 20 typosquatting/phishing apps in the Chinese Apple App Store which direct victims to provisioning-profile-based installs or WebView phishing pages that collect and exfiltrate wallet recovery phrases and private keys; the report includes detailed technical analysis of malicious dylibs and React Native implants, POST exfiltration formats, C2 domains, file hashes, distribution links, observed Android variants, victim targeting (primarily China), and an attribution link to SparkKitty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.