Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Dozens of Malicious Crypto Apps Land in Apple App Store
    Cybersecurity

    Dozens of Malicious Crypto Apps Land in Apple App Store

    adminBy adminApril 21, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    iOS Update
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Over two dozen fake cryptocurrency applications targeting iOS users have been published to the Apple App Store, Kaspersky reports.

    The malicious campaign, dubbed FakeWallet, has been ongoing since at least the fall of 2025, focused on stealing users’ recovery phrases and private keys.

    The apps, Kaspersky says, were first noticed in March, after they started to frequently appear in search results on the Chinese App Store.

    Because many official wallet applications are currently unavailable to users in China due to restrictions, threat actors have started mimicking their names and icons, using typosquating to trick users into believing they are downloading legitimate software.

    Although some of the apps did not use cryptocurrency-associated names or icons, they displayed banners enticing users to download the apps to access official wallets that were not available in the App Store.

    Kaspersky identified a total of 26 such phishing applications that mimicked major wallets such as Bitpie, Coinbase, imToken, Ledger, MetaMask, TokenPocket, and Trust Wallet.

    Advertisement. Scroll to continue reading.

    Additionally, the cybersecurity firm identified several other applications that did not include phishing functionality but were linked to the same threat actor.

    “It’s highly likely that the malicious features were simply waiting to be toggled on in a future update,” Kaspersky says.

    The phishing applications were designed to open a link in the browser in an attempt to trick the user into installing infected versions of crypto wallets. The malicious code was typically delivered via libraries, but in some cases, it was injected directly into the wallet’s source code.

    Code analysis revealed the presence of functions to harvest users’ recovery phrases and seed phrases, and to hijack the methods the app calls when users attempt to restore their hot wallets. Furthermore, the applications were found to target cold wallets through two Ledger implants.

    Kaspersky identified a website mimicking the official Ledger site hosting links to these applications, as well as compromised wallet apps for Android distributed through Chinese-language phishing pages, but not through the Play Store.

    According to the cybersecurity firm, while the apps appear to target Chinese speakers, the malicious modules do not have built-in regional restrictions, and some phishing notifications were seen adapting to the app’s language, suggesting that users outside China could be targeted as well.

    The threat actor responsible for the FakeWallet campaign appears linked to the SparkKitty malware that was uncovered in June last year, based on the distribution technique, focus on cryptocurrency wallets, Chinese log messages in the malicious modules, and the presence of SparkKitty modules in some applications.

    Apple has been notified and it has started removing the malicious apps. 

    Related: Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit

    Related: Coruna iOS Exploit Kit Likely an Update to Operation Triangulation

    Related: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’

    Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

    app Apple apps Crypto dozens land Malicious Store
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleCopyright and DMCA Best Practices for Fediverse Operators
    Next Article French govt agency confirms breach as hacker offers to sell data
    admin
    • Website

    Related Posts

    AI Apps You Can Use Right Now to Grow Your Website

    June 5, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google’s Updated Guidance Urges FTC Complaints Against Shady SEOs

    June 6, 2026

    4 ways to track AI search visibility when attribution falls short

    June 6, 2026

    Google’s Sergey Brin Sees A Path To AGI But Not Beyond It

    June 6, 2026

    Bots now make up 57% of webpage requests

    June 6, 2026
    Categories
    • Blogging (90)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (242)
    • SEO & Digital Marketing (1,394)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (336)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google’s Updated Guidance Urges FTC Complaints Against Shady SEOs

    June 6, 2026

    4 ways to track AI search visibility when attribution falls short

    June 6, 2026

    Google’s Sergey Brin Sees A Path To AGI But Not Beyond It

    June 6, 2026
    Most Popular
    • Google’s Updated Guidance Urges FTC Complaints Against Shady SEOs
    • 4 ways to track AI search visibility when attribution falls short
    • Google’s Sergey Brin Sees A Path To AGI But Not Beyond It
    • Bots now make up 57% of webpage requests
    • Google Tests AI Search Data, UK Requires Opt Out
    • Microsoft expands Audience Ads eligibility for cryptocurrency exchanges
    • Internet Age-Gates Are a Growing Global Threat
    • AI Literacy Is Not Prompt Literacy. Ann Handley Says It’s Judgment Literacy
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.