FakeWallet crypto stealer spreading through iOS apps in the App Store
ID: 73ce0413-f4ff-557a-9ab9-1a4f01c82d2b
STIX ID: report--73ce0413-f4ff-557a-9ab9-1a4f01c82d2b
Feed Name: Securelist by Kaspersky
In March 2026 researchers uncovered a coordinated FakeWallet campaign that published phishing apps in the Apple App Store (primarily targeting Chinese users) which redirect victims to malicious provisioning profiles or webviews to install trojanized crypto wallets; those implants scrape BIP-39 recovery phrases/private keys, encrypt and exfiltrate them to hardcoded C2 servers. The report provides implementation details (library injection, custom __hook sections, React Native tampering), example C2 URLs and hashes, additional Android instances, and ties to SparkKitty modules, warning of significant financial theft risk for affected users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
