SlowMist|Sep 20, 2026 14:51
🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the @okx, @OKXWallet_CN security team.
Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that #FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore.
Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection.
🧵👇
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink