🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the
@okx,
@OKXWallet_CN security team.
Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that
#FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore.
Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection.
🧵👇