Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Dozens of Malicious Crypto Apps Land in Apple App Store
    Cybersecurity

    Dozens of Malicious Crypto Apps Land in Apple App Store

    adminBy adminApril 21, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    iOS Update
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Over two dozen fake cryptocurrency applications targeting iOS users have been published to the Apple App Store, Kaspersky reports.

    The malicious campaign, dubbed FakeWallet, has been ongoing since at least the fall of 2025, focused on stealing users’ recovery phrases and private keys.

    The apps, Kaspersky says, were first noticed in March, after they started to frequently appear in search results on the Chinese App Store.

    Because many official wallet applications are currently unavailable to users in China due to restrictions, threat actors have started mimicking their names and icons, using typosquating to trick users into believing they are downloading legitimate software.

    Although some of the apps did not use cryptocurrency-associated names or icons, they displayed banners enticing users to download the apps to access official wallets that were not available in the App Store.

    Kaspersky identified a total of 26 such phishing applications that mimicked major wallets such as Bitpie, Coinbase, imToken, Ledger, MetaMask, TokenPocket, and Trust Wallet.

    Advertisement. Scroll to continue reading.

    Additionally, the cybersecurity firm identified several other applications that did not include phishing functionality but were linked to the same threat actor.

    “It’s highly likely that the malicious features were simply waiting to be toggled on in a future update,” Kaspersky says.

    The phishing applications were designed to open a link in the browser in an attempt to trick the user into installing infected versions of crypto wallets. The malicious code was typically delivered via libraries, but in some cases, it was injected directly into the wallet’s source code.

    Code analysis revealed the presence of functions to harvest users’ recovery phrases and seed phrases, and to hijack the methods the app calls when users attempt to restore their hot wallets. Furthermore, the applications were found to target cold wallets through two Ledger implants.

    Kaspersky identified a website mimicking the official Ledger site hosting links to these applications, as well as compromised wallet apps for Android distributed through Chinese-language phishing pages, but not through the Play Store.

    According to the cybersecurity firm, while the apps appear to target Chinese speakers, the malicious modules do not have built-in regional restrictions, and some phishing notifications were seen adapting to the app’s language, suggesting that users outside China could be targeted as well.

    The threat actor responsible for the FakeWallet campaign appears linked to the SparkKitty malware that was uncovered in June last year, based on the distribution technique, focus on cryptocurrency wallets, Chinese log messages in the malicious modules, and the presence of SparkKitty modules in some applications.

    Apple has been notified and it has started removing the malicious apps. 

    Related: Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit

    Related: Coruna iOS Exploit Kit Likely an Update to Operation Triangulation

    Related: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’

    Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

    app Apple apps Crypto dozens land Malicious Store
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleCopyright and DMCA Best Practices for Fediverse Operators
    Next Article French govt agency confirms breach as hacker offers to sell data
    admin
    • Website

    Related Posts

    22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters

    April 22, 2026

    Big banks seek to ease security worries as AI push accelerates

    April 21, 2026

    French govt agency confirms breach as hacker offers to sell data

    April 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    5 reasons you definitely shouldn’t use “Ultra” settings in video games

    April 22, 2026

    22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters

    April 22, 2026

    SmartTube beta (Android TV) 31.60 APK Download by yuliskov

    April 22, 2026

    Big banks seek to ease security worries as AI push accelerates

    April 21, 2026
    Categories
    • Blogging (66)
    • Cybersecurity (1,436)
    • Privacy & Online Earning (176)
    • SEO & Digital Marketing (872)
    • Tech Tools & Mobile / Apps (1,722)
    • WiFi / Internet & Networking (237)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    5 reasons you definitely shouldn’t use “Ultra” settings in video games

    April 22, 2026

    22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters

    April 22, 2026

    SmartTube beta (Android TV) 31.60 APK Download by yuliskov

    April 22, 2026
    Most Popular
    • 5 reasons you definitely shouldn’t use “Ultra” settings in video games
    • 22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters
    • SmartTube beta (Android TV) 31.60 APK Download by yuliskov
    • Big banks seek to ease security worries as AI push accelerates
    • Google rolls out new AI safety features in Ads Advisor
    • How Zero Networks is closing the network enforcement gap for AI agents
    • French govt agency confirms breach as hacker offers to sell data
    • Dozens of Malicious Crypto Apps Land in Apple App Store
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.