FomoPeek Trojanized iOS App Hides Kernel Exploit to Steal Cryptocurrency Wallet Data
Scope: iOS Devices with FomoPeek or Similarly Sideloaded Cryptocurrency Applications Installed
Severity: Red
Security researchers identified a malicious iOS application named FomoPeek, distributed outside Apple's official App Store, that embeds a kernel-level exploit designed to escalate privileges on the device and exfiltrate cryptocurrency wallet data, private keys, and exchange session information without the user's knowledge. Because the app is sideloaded rather than distributed through the App Store, it bypasses Apple's standard app review and sandboxing protections, giving the embedded exploit direct access to sensitive system components that would otherwise be isolated. Any device that has installed FomoPeek or a similar unofficial cryptocurrency-related application should be treated as compromised, since a kernel-level exploit can persist and access data well beyond what the visible app interface suggests. Users must delete the app immediately if found, avoid installing any application from outside the official App Store regardless of how it is promoted, and reset the affected device before rotating all credentials linked to cryptocurrency wallets and exchange accounts that may have been accessed from it.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.