Malicious iOS app linked to 580,000 USDT theft
Blockchain security firm SlowMist has linked a malicious iOS application distributed through Apple's App Store to the theft of nearly 580,000 USDT, after the app used kernel exploits to break out of Apple's sandbox and reach sensitive data stored by other applications. The app, called FomoPeek, was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron. According to SlowMist, versions 1.1 and 1.2, released on Sept. 9 and Sept. 12, contained two malicious modules with eight kernel exploit methods. The components were removed in version 1.3, released on Sept. 17. Version 1.0 did not contain the modules. SlowMist said its investigation, conducted jointly with the OKX security team, began after users reported crypto theft and confirmed they had installed FomoPeek builds from the affected period. One module communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework that could adjust to the victim's iPhone model and operating system version. SlowMist said the framework declared support for iOS versions 12.0 to 18.7.2 and 26.0 to 26.