吴说区块链
吴说区块链|Sep 20, 2026 15:23
SlowMist, together with the OKX and OKX Wallet security teams, has jointly analyzed and confirmed that the official FomoPeek App Store versions 1.1 (September 9) and 1.2 (September 12) contained malicious modules `apptrace` and `libapptracecore`. These modules have capabilities such as remote control, iOS kernel exploitation, privilege escalation, sandbox escape, Keychain decryption, and cross-app data collection. The related modules were removed in version 1.3 (September 17). Dynamic verification shows that the attack chain can collect device information, installed app lists, wallet app data, and Keychain data, and during testing, successfully uploaded Apple Notes database files. MistTrack tracing indicates that the related funds were transferred across networks like TRON, Ethereum, and BNB Chain, with the main hacker address receiving approximately 579,984 USDT. SlowMist recommends that users who have installed versions 1.1 or 1.2 stop using the app and avoid reinstalling it. Instead, create a new wallet on a clean device that has never installed the app, migrate assets, replace related credentials, and review transaction and authorization records. https://(wublock123.com)/news/fomopeek-1-1-1-2-malicious-module-ios-kernel-data-theft-68708
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads