logo

China's Apple App Store infiltrated by crypto-stealing wallet apps

ID: 1b2f0cad-b828-5d8d-afea-13ca88d4147a

STIX ID: report--1b2f0cad-b828-5d8d-afea-13ca88d4147a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Kaspersky/BleepingComputer-sourced report describes the FakeWallet campaign in which 26 trojanized iOS apps impersonated popular cryptocurrency wallets (e.g., MetaMask, Coinbase, Trust Wallet) to phish and intercept seed/recovery phrases via fake sites and sideloaded apps using iOS provisioning profiles; stolen mnemonics were encrypted and exfiltrated, enabling attackers to restore and drain victims' wallets, primarily targeting users in China but technically capable of affecting users globally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.