Security Teams Expose High-Risk Malicious Code in Old App Versions
According to a recent security alert issued by SlowMist, their joint investigation with the OKX security team into multiple cases of user asset theft has uncovered a common source of risk. The investigation indicates that some affected users had previously installed or used versions 1.1 to 1.2 of the FomoPeek application. Deep-dive analysis revealed that these specific versions contained malicious code modules unrelated to the app's legitimate functions, posing a severe security threat.
Technical Details and Capabilities of the Malicious Module
Security researchers identified an iOS kernel exploit framework within the app. The danger of this framework lies in its high adaptability and automation.
- Broad System Coverage: The framework supports attacks against iOS versions 12.0 to 18.7, and 26.0 to 26.1.
- Intelligent Attack Selection: It can automatically select the most effective method from eight different exploitation techniques based on the detected device model and iOS version.
- Core Objective: Sandbox Escalation. If successful, the malicious code can break out of iOS's strict application sandbox restrictions.
Upon sandbox escape, the attacker's primary goal is to access and decrypt data stored in the system Keychain. This directly puts the following core sensitive information at risk of exposure:
- Private keys and mnemonics for cryptocurrency wallets
- Login credentials (usernames, passwords) for various applications
- Other sensitive files and user data stored on the device
An Ongoing and Remote Threat
More concerning is that this threat is not dormant. SlowMist confirmed through analysis of captured network traffic that these malicious attack functions are currently enabled and run automatically at regular intervals. Furthermore, the app connects in the background to a hidden server unrelated to its public services, suggesting attackers may have the capability to issue remote commands and control affected devices.
Urgent Security Action Guide for Users
If you have ever installed or used FomoPeek version 1.1 or 1.2, you should immediately take the following steps to protect your assets and personal information:
- Conduct an Immediate Asset Security Check: Carefully review transaction records for all associated wallets and exchange accounts to check for any unauthorized transfers or activity.
- Generate New Keys on a Secure Device: On a trusted device that has never had this app installed, generate completely new private keys and mnemonics for all your digital asset wallets. This is a crucial step to isolate the risk.
- Transfer Assets Promptly: Move all assets from the original addresses to new, secure addresses controlled by the new keys.
- Update Your Operating System: Immediately update your iOS device to the latest version provided officially. System updates often patch known security vulnerabilities and can help defend against attacks from such exploit frameworks.
- Permanently Discontinue the Risky App: Do not continue using FomoPeek versions 1.1-1.2, and do not reinstall it. Maintain vigilance regarding apps from unofficial channels.
This incident serves as another reminder that downloading applications from unofficial stores or unknown sources can carry significant security risks. Keeping your system updated and installing software only from trusted sources are fundamental defenses for safeguarding your digital assets.