Crypto World

Crypto-draining FOMO app was available on Apple store for a week

Published

on

Analysts have urged iPhone users to update their IOS after crypto-stealing malware was discovered in malicious Safari browser links and the FOMO app.

SlowMist’s Chief Information Security Officer, Shān Zhang, encouraged his followers last Saturday to update to the latest version of IOS following the proliferation of DarkSword malware.

He claims iPhone versions IOS 13 to IOS 26.5 leave you vulnerable to malicious Safari links that utilize a memory-corruption flaw in WebKit and JavaScriptCore.

This gives hackers access to the JavaScript layer for read and write access.

Advertisement

Hackers can then bypass pointer authentication codes, escape the WebContent sandbox, and escalate kernel privileges in order to gain root access and make unauthorised changes allowing for the exfiltration of crypto keys and wallet data.

Read more: Google warns over 200 million iPhone crypto wallets at risk

FOMO official app contained malware for a week

SlowMist also warned about crypto draining malware across official versions of the FOMO app on the App Store that users may have downloaded thanks to the promotion of crypto key opinion leaders. 

SlowMist’s report on the malicious apps found it contained malware hidden with modules that were similarly capable of the DarkSword exploits, and can lead to the theft of seed phrases and private keys. 

Advertisement

The vulnerable versions were active between September 9 and September 17.

SlowMist says updating or deleting the app may not be enough, and that users should treat their “relevant seed phrases, private keys, and sensitive credentials as compromised.” 

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Advertisement




Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version