Security researchers have discovered malicious code embedded within official versions of the FomoPeek application on the Apple App Store, exposing user data from Apple Notes and threatening cryptocurrency assets. According to a threat intelligence report published by blockchain security firm SlowMist, the rogue modules appeared in versions 1.1 and 1.2 of the app, which was marketed as an on-chain portfolio monitoring tool.
Apple App Store Security Breach: FomoPeek Exposes iPhone Data and Crypto Wallets
The malicious code successfully bypassed iOS security protections to harvest container data and communicate with a remote server. Investigators linked the operation to a wallet address that accumulated 579,984.34 USDT across multiple blockchain networks following a surge in activity beginning September 15, according to SlowMist data.
Malicious Code Discovery and App Store Distribution
FomoPeek entered the Apple App Store disguised as a read-only tracking utility that did not require seed phrases or direct wallet connections. However, according to SlowMist’s analysis, that interface concealed backdoor modules designed to extract sensitive device data. Investigators compared multiple App Store versions and confirmed the malicious files shared the exact developer signature as legitimate builds, proving the software was compromised prior to distribution rather than altered post-download.
The unauthorized modules appeared in version 1.1, released on September 9, and version 1.2, released on September 12. They were absent from version 1.0 and subsequently removed in version 1.3 on September 17. SlowMist tracked the financial impact to a primary attacker address that became active on September 15, receiving 579,984.34 USDT through various blockchain swaps. Investigators noted this figure represents total wallet inflows rather than a verified total of direct cryptocurrency theft.
Exploit Testing and Targeted Applications
During controlled isolation testing, security researchers documented how the hidden modules retrieved encrypted server addresses from Bitbucket to receive operational commands. According to SlowMist, the remote server controlled payload delivery and evaluated whether the target iPhone exhibited vulnerabilities. When researchers enabled the exploit module in a sandboxed environment, the app deployed a targeting list covering 19 distinct crypto wallet and note-taking applications.
Investigators intercepted network traffic showing the app successfully packaging and uploading the Apple Notes data container to the remote command server. The app’s codebase incorporated a strategy designated as DarkSwordStrategy, sharing nomenclature with the DarkSword iOS exploit chain documented by the Google Threat Intelligence Group in March. While the testing proved the code’s capability to exfiltrate private notes, researchers emphasized that actual data harvested from individual consumer devices depends on activation triggers sent by the remote server.
Precedents and Risk Mitigation for Users
The FomoPeek compromise follows a series of app-based security incidents targeting cryptocurrency holders on major mobile platforms. In July, three investors reported significant financial losses after downloading a counterfeit Sparrow Wallet app that harvested seed phrases directly. Similarly, an investigator linked a fraudulent Ledger app to asset thefts reported in April. Unlike those direct-input scams, FomoPeek posed a unique threat because users had no functional reason to suspect a portfolio monitor would access private data stored elsewhere on their devices.
SlowMist advised anyone who installed FomoPeek version 1.1 or 1.2 to treat all private keys, seed phrases, and sensitive credentials stored on those devices as permanently compromised. Because data transmitted during the active infection window cannot be retrieved or erased remotely, security experts recommend generating new wallets on clean hardware completely isolated from the compromised iPhone and transferring remaining digital assets immediately.
Worth a look