New iOS Threat Targets Crypto Wallets: Inside the FomoPeek Malware Campaign
A recent analysis by cybersecurity firms has shed light on a malicious third-party application called FomoPeek, posing a direct threat to user devices and the security of digital assets.
How the Attack Works
The malicious variant of FomoPeek exploits specific vulnerabilities within the iOS operating system. Upon installation, it can gain unauthorized access to the device, aiming to harvest sensitive data stored locally.
According to the published investigation, the command-and-control (C2) servers used by the attackers issued data collection commands targeting several prominent cryptocurrency wallet applications. The list of potentially affected wallets includes:
- Gate Web3
- SafePal
- OKX Wallet
- MetaMask
- Trust Wallet
- imToken
- TokenPocket
- TronLink
Notably, Binance Wallet was not listed among the affected applications in the currently disclosed reports.
Binance's Stance and User Advisory
In response to the incident, a Binance spokesperson confirmed that internal checks found no evidence linking the disclosed FomoPeek attack vectors to Binance Wallet. The platform has also not received any user reports of impact related to this event.
The spokesperson reiterated that user asset and product security remains a top priority, with ongoing security monitoring and risk assessment procedures in place. The team is committed to taking immediate action should any new threats be identified.
Following the security disclosures, Binance proactively issued a safety notice to its users. The advisory urges individuals to scan their mobile devices for any suspicious applications, particularly one named FomoPeek, and to uninstall it immediately if found. Users are also advised to keep their device operating systems updated and to reinforce the security measures for their wallet assets.
This incident serves as a critical reminder of the persistent risks associated with managing crypto assets on mobile devices. Vigilance, coupled with downloading apps only from official sources and maintaining updated software, is essential for protection.