The discovery, supported by investigations from firms including SlowMist and the OKX security team, reveals that the malware leverages an iOS kernel exploitation framework. This framework, which includes eight distinct attack methods, allows the application to gain high-level privileges and decrypt Keychain data. Unlike typical phishing attempts, this code operates silently in the background, communicating with remote infrastructure to receive instructions and exfiltrate data from other installed applications.
Historical analysis shows the malicious frameworks were introduced to FomoPeek on September 9 and remained active until their removal in version 1.3 on September 17. Because these versions were distributed through Apple’s official App Store, users may have installed them under the assumption of legitimacy. Affected individuals are advised to immediately remove the application and avoid reinstalling it. Binance recommends that users create new, secure wallets on a clean device that has never hosted the compromised software, subsequently transferring all assets to these new addresses to mitigate the risk of further unauthorized access.

Comments (0)
No comments yet. Be the first!