Last updated 2 months ago
Apple's App Store hosted 26 malicious applications impersonating popular cryptocurrency wallets, discovered by Kaspersky researchers. The campaign has been active since at least fall 2025, targeting users to steal recovery phrases and private keys. No specific number of affected users or financial losses has been disclosed.
The attack chain involves users downloading fake wallet apps from the official App Store. Once launched, these apps redirect victims to browser pages mimicking the App Store interface, distributing trojanized versions of legitimate wallets. The malware captures cryptocurrency seed phrases and private keys upon user input, enabling attackers to drain wallets. No specific threat actor has been attributed, and no CVEs or MITRE ATT&CK techniques were cited.
Apple has removed the identified malicious apps from the App Store. No further details on regulatory actions, litigation, or remediation milestones have been reported.
Malicious apps impersonating cryptocurrency wallets redirect users to fake App Store pages to distribute trojanized versions of legitimate wallets, stealing recovery phrases and private keys.
Sign in to join the discussion.
Company
Industry
Location
Discovered
Disclosed
Records Affected
Attack Vector