started · updated
FomoPeek malware targets iOS users to steal crypto keys
Security firms Binance and SlowMist have issued warnings regarding FomoPeek, a third-party application containing malicious code in versions 1.1 and 1.2. The malware utilizes an advanced iOS exploit framework capable of bypassing the Apple operating system's application sandbox to obtain high-level privileges.
Research conducted by SlowMist and the OKX security team indicates the exploit can access protected areas of a device, including the Keychain. This allows the malware to potentially steal private keys, seed phrases, login credentials, chat histories, and personal files. The framework is designed to automatically select attack methods based on the specific device model and iOS version, affecting a wide range of software from iOS 12.0 up to version 26.5.
Because the malware targets the device itself rather than a specific application, it can expose data from various other apps installed on the device. Experts advise users who have installed affected versions to remove the application immediately, update their operating system, and, for self-custody wallet users, create new wallets on clean devices to transfer assets to new addresses.