FomoPeek app versions 1.1–1.2 exposed users to asset theft risks

Summary

A security alert has been issued regarding the FomoPeek app, specifically versions 1.1 and 1.2, after reports of asset theft due to private key exposure linked to the app's malicious code. The joint investigation by @SlowMist_Team and @okx security teams revealed that the app includes a kernel exploitation framework, which can access sensitive data stored on devices running iOS 12.0–18.7 and iOS 26.0–26.1. Users are advised to cease using the app, check for unusual account activity, and update their iPhones to the latest iOS version to mitigate risks from potential exploitation.

Analysis

okx: OKX is a cryptocurrency exchange that maintains a security team focused on protecting users and investigating threats in the ecosystem. Its security team joined the joint investigation with SlowMist Team to analyze the FomoPeek app and confirm the presence of malicious code. The collaboration supported the alert regarding asset theft risks from the affected app versions. FomoPeek: FomoPeek is a mobile application with stated business functions that also incorporated additional hidden modules in certain versions. SlowMist Team and OKX security teams identified malicious code in the app capable of iOS kernel exploitation and remote command execution. The news highlights risks from versions 1.1–1.2, which exposed users to private key theft and sandbox escape on affected devices. SlowMist Team: SlowMist Team is a blockchain security firm specializing in threat detection and incident investigation for crypto-related applications and platforms. It received user reports of asset theft, conducted analysis confirming malicious elements in FomoPeek, and issued a public alert with mitigation steps. The team collaborated with OKX security on confirming the threat details. FomoPeek app v1.1: FomoPeek app v1.1 refers to a specific early version of the FomoPeek mobile application that included undisclosed malicious modules alongside its normal features. Analysis showed these modules enabled automatic iOS kernel exploits leading to potential private key exposure. The version is directly tied to multiple reported asset theft incidents prompting the security alert. FomoPeek app v1.2: FomoPeek app v1.2 refers to a subsequent version of the FomoPeek mobile application that retained the malicious code and hidden server connections identified in prior releases. It automatically ran attack functionality at intervals and affected a range of iOS versions. Users of this version were advised against continued use or reinstallation due to ongoing risks. iOS Exploitation: iOS kernel exploitation frameworks can enable sandbox escapes allowing access to device Keychain data and files from other apps. App Security Risks: Apps connecting to hidden servers and receiving remote commands pose ongoing threats to sensitive data including private keys and credentials.

Categories

cryptotechripple
View Original Tweet