FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked, Chinese-speaking Actor)
FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 (TL-2026-0395), also tracked as FakeWallet crypto stealer, is a critical-severity malware campaign, first published 2026-04-20. It is attributed to FakeWallet operators (China) with medium confidence, affects ConsenSys MetaMask (impersonated), maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 56 indicators of compromise.
Key facts for TL-2026-0395
- Threat ID
- TL-2026-0395
- Also known as
- FakeWallet crypto stealer, HEUR:Trojan-PSW.IphoneOS.FakeWallet, HEUR:Trojan.IphoneOS.FakeWallet
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-04-20
- Last reviewed
- 2026-04-20
- Attribution
- FakeWallet operators
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, financial, consumer, web3, individual-investors, high-net-worth-individuals
- Target regions
- China, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 56
Malware and tooling in FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
Malware and tooling: FakeWallet, SparkKitty, Custom PHP C2 (Rsakeycatch.php / Rsakeyword.php / receiRsakeyword.php)
Kaspersky Securelist disclosed 26 phishing iOS applications distributed through the official Apple App Store — most concentrated in the Chinese storefront — impersonating MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. The FakeWallet family (Kaspersky: HEUR:Trojan-PSW.IphoneOS.FakeWallet.*) exfiltrates BIP-39 seed phrases by combining dylib library injection, Objective-C method swizzling of viewDidLoad on recovery-phrase screens, view-controller hierarchy traversal, custom __hook Mach-O sections, and React Native payloads. Stolen mnemonics are RSA-PKCS#1 encrypted, Base64-encoded, and POSTed to C2 endpoints on kkkhhhnnn[.]com, helllo2025[.]com, sxsfcc[.]com, iosfc[.]com, nmu8n[.]com, zmx6f[.]com, and api.dc1637[.]xyz. Tooling and campaign infrastructure overlap with the SparkKitty trojan, and log strings plus Chinese-language phishing pages attribute the operation to a Chinese-speaking actor with operator metadata dating to at least fall 2025. Both hot-wallet (silent recovery-phrase scraping) and cold-wallet (in-app phishing WebView prompting the victim to 'verify' their seed phrase) vectors are in active use, placing every crypto user who sideloads one of the impersonator apps at immediate risk of full wallet drain.
How FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 works
On 20 April 2026, Kaspersky Securelist (Sergey Puzan, GReAT) published a technical deep-dive revealing that throughout March 2026 the Apple App Store — particularly the Chinese storefront — was flooded with phishing applications masquerading as well-known cryptocurrency wallets. Kaspersky identified 26 such apps spanning MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. Because Apple's regional policies block the legitimate wallet apps for users whose Apple ID is set to the China region, the FakeWallet operators weaponised typosquatting (mimicked icons, intentionally misspelled names) and deceptive promotional banners that claimed the 'official wallet is unavailable in the App Store' to drive installs. Several of the apps have since been pulled following Kaspersky's disclosure to Apple, but additional dormant apps without yet-activated phishing logic remain in the ecosystem and are positioned for a switch-flip via future update.
Each App Store app itself is only a stub — a calculator, task planner, or small game — whose real purpose is to open a browser link on launch. That link pivots the victim through a malicious enterprise provisioning-profile install of a trojanised wallet build. Enterprise provisioning profiles were designed for corporate in-house app distribution, but have long been abused by cracked-app, casino, cheat, and malware operators — and are the same profile type that SparkKitty leveraged. The installed payload then behaves in one of three technical patterns depending on the target wallet.
Pattern 1 — Hot wallet injection via dylib + Objective-C swizzling: The attackers add extra load commands to the main Mach-O executable so the dyld linker pulls in a malicious library (e.g. libokexHook.dylib in the Coinbase clone). Initialisation routines — either Objective-C +[UIViewController load] and +[UIView load] methods, or C++ static initialisers in __mod_init_functions — swap the original viewDidLoad of the recovery-phrase screen (e.g. RecoveryPhraseViewController) with a hijacked version. The hooked viewDidLoad walks the current view controller's subview tree, extracts mnemonic words as they are entered, concatenates them, encrypts the resulting string with RSA using PKCS #1 padding, Base64-encodes the ciphertext, and POSTs it together with a module type, app name, and a hardcoded unique code to a C2 URL of the form /api/open/postByTokenPocket?ciyu=<b64>&code=10001&ciyuType=1&wallet=<name>.
Pattern 2 — Trust Wallet __hook trampoline: Instead of initialisation hooks, the attackers append a custom __hook section to the main executable, placed just before __text in the region normally reserved for load commands. The first two entries are trampolines resolving dlsym and the original WalletCore mnemonic-validation routine; the next pair are wrappers that resolve the symbols dataInit or processX0Parameter from the malicious library, hand control to them, and then execute the original replaced method. This rewires every code path where the app validates, imports, or generates a seed phrase, leaking the mnemonic to the C2 before the legitimate logic runs.
Pattern 3 — Ledger cold-wallet phishing via malicious library or React Native tamper: Because Ledger Live is a UI front for a hardware wallet and cannot silently read recovery phrases, the attackers use in-app phishing. In the library variant, an entry function loads a config file containing C2 URL (e.g. hxxps://iosfc[.]com/ledger/ios/Rsakeycatch.php), a numeric 'code' such as 10001, and a login-url plus login-code. +[UIViewController load] and +[UIView load] overrides traverse the view hierarchy; when a screen named add-account-cta or one containing a $ sign is rendered, the malware identifies the locale from the 'add account' button text, constructs a localised 'security check' phishing notification, and stores it in GlobalVariables. When the victim subsequently opens an account-add or buy/sell screen, the notification surfaces and opens a WebView pointing at a local verify.html bundled inside the app. verify.html mimics the Ledger UI, enforces BIP-39 dictionary validation on the entered words (rejecting anything off-list to raise credibility), offers autocomplete for mnemonic words, and forwards the completed phrase to an Objective-C handler that encrypts it with RSA PKCS #1, Base64-encodes it, and sends it to the C2. The second Ledger variant patches the React Native JavaScript bundle directly — Ledger Live is open-source — inserting two new screens, MnemonicVerifyScreen (embedded in PortfolioNavigator) and PrivateKeyVerifyScreen (embedded in MyLedgerNavigator). The phishing screens only trigger once a hardware wallet is paired, a deliberate anti-analysis guardrail. Three state files are written to the app directory: verify-wallet-status.json (timestamped progress tracker), verify-wallet-config.json (current C2 configuration), and verify-wallet-pending.json (encrypted mnemonics awaiting transmission; cleared via clearPendingMnemonicJob on success). A dedicated exfil thread resumes pending sends if the app is relaunched.
Infrastructure and cross-platform reach: Kaspersky also discovered a phishing website cloning the official Ledger landing page that served the same iOS payloads plus Android APKs — some previously undocumented — linked via enterprise-profile install flows. No Google Play presence was observed; Android distribution is confined to attacker-controlled sites. Several infected iOS apps contained dormant SparkKitty modules alongside the FakeWallet code, a strong link given SparkKitty's own 2025 campaign used the same enterprise-profile/phishing-page-mimicking-App-Store delivery model, shared Chinese-language log strings, and pursued the same cryptocurrency-theft objectives. Kaspersky assesses with medium-to-high confidence that the two campaigns share operators or are closely collaborating.
Victimology: Near-exclusive Chinese-language phishing pages and Chinese App Store prevalence indicate Chinese-speaking crypto users are the primary targets, but the modules contain no locale gating and some variants auto-localise phishing notifications — any iOS user who ends up on one of the phishing redirects or sideloads a trojanised build via enterprise profile is exposed. The financial impact is severe: a single successful exfiltration transfers full BIP-39 entropy and therefore complete control of every account derivable from the seed, across every chain the wallet supports. Defenders protecting high-net-worth users or on-call IR for Web3 / exchange / custody operations should treat any Chinese-region App Store install of a wallet-themed app as presumptively compromised until proven otherwise, and should hunt for the hashes, C2 domains, and behavioural IOCs enumerated below across mobile-management, proxy, and DNS telemetry.
MITRE ATT&CK techniques used in TL-2026-0395
Collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056.002 Input Capture: GUI Input Capture; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1132.001 Data Encoding: Standard Encoding; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.002 Encrypted Channel: Asymmetric Cryptography
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1566.002 Phishing: Spearphishing Link
Execution
T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File; T1575 Native API
Persistence
T1546 Event Triggered Execution; T1554 Compromise Host Software Binary
defense-impairment
T1553.006 Subvert Trust Controls: Code Signing Policy Modification
stealth
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
Impact
Affected products and versions in FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
- ConsenSys — MetaMask (impersonated)
Vulnerable versions: users who installed typosquatted App Store clones
Fixed in: install official MetaMask from vendor site on unaffected region - Ledger — Ledger Live (impersonated and trojanised builds)
Vulnerable versions: iOS clone distributed via Chinese App Store and phishing sites; React Native bundle modified variant
Fixed in: install Ledger Live from ledger.com - Trust Wallet — Trust Wallet (impersonated)
Vulnerable versions: trojanised iOS build with __hook section
Fixed in: install from trustwallet.com - Coinbase — Coinbase Wallet (impersonated)
Vulnerable versions: iOS clone injected with libokexHook.dylib
Fixed in: install from coinbase.com - TokenPocket — TokenPocket (impersonated)
Vulnerable versions: iOS clones on Chinese App Store and enterprise-profile distributions
Fixed in: install from tokenpocket.pro - imToken — imToken (impersonated)
Vulnerable versions: iOS clones on Chinese App Store
Fixed in: install from token.im - Bitpie — Bitpie (impersonated)
Vulnerable versions: iOS clones on Chinese App Store
Fixed in: install from bitpie.com - Apple — Apple App Store (distribution channel abuse)
Vulnerable versions: Chinese storefront submissions bypassed initial filters via typosquatting and benign-stub apps
Fixed in: Apple continuing takedowns of reported apps - Apple — iOS enterprise provisioning profiles (abuse mechanism)
Vulnerable versions: all iOS versions supporting enterprise/provisioning profile installs
Fixed in: user action: do not install unknown profiles
Remediation for FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
Patches
- No CVE applies. Follow Apple's App Store takedowns — several of the 26 apps have already been removed; monitor Apple Platform Security advisories for any related provisioning-profile tightening.
- Update all managed iOS devices to the latest iOS build to ensure enterprise-profile trust prompts and unsigned-dylib enforcement are current.
Immediate actions
- Alert all iOS users to immediately delete any wallet-themed app installed from the Chinese App Store in the last 60 days and rotate seed phrases by generating a brand-new wallet and transferring funds.
- Block the C2 domains kkkhhhnnn[.]com, helllo2025[.]com, sxsfcc[.]com, iosfc[.]com, nmu8n[.]com, zmx6f[.]com, and api.dc1637[.]xyz at corporate proxy, DNS, and secure-web-gateway tiers.
- Block the phishing/distribution hosts gxzhrc[.]cn, appstoreios[.]com, crypto-stroe[.]cc, yjzhengruol[.]com, jhxrpbgq[.]com, apps-store[.]im, oukwww[.]com, lahuafa[.]com, ulbcl[.]com, siyangoil[.]com, ahroar[.]com, and IP 139.180.139[.]209 in egress filters.
- Push a mobile-device-management (MDM) policy that forbids installation of enterprise provisioning profiles from non-corporate issuers and revokes any unknown MDM profile currently present on managed iOS devices.
- Ingest the 17 FakeWallet file hashes into the EDR/MDM file-reputation allowlist as known-bad.
Workarounds
- Remove all enterprise provisioning profiles from iOS devices (Settings -> General -> VPN & Device Management) that are not issued by the employer's own MDM.
- For crypto users who already entered a seed phrase into any suspect wallet app, treat that wallet as fully compromised: generate a new seed phrase on a known-good hardware device and migrate all funds immediately.
Longer-term hardening
- Deploy a mobile threat defense (MTD) product capable of static analysis of IPA files so enterprise-distributed iOS apps can be scanned for dylib injection, extra __hook sections, and atypical Mach-O load commands.
- Establish a corporate policy prohibiting the use of personal crypto wallet apps on managed devices; require hardware wallets only and pair them through verified desktop applications.
- Educate executive and finance staff that Chinese App Store regional restrictions do NOT justify sideloading — legitimate wallets that are region-blocked should never be installed via enterprise profile, provisioning profile, or third-party store.
- Subscribe to Apple's ongoing App Store integrity disclosures and SparkKitty/FakeWallet indicator feeds; wire hash and domain feeds into SIEM via STIX/TAXII.
- Implement DNS-layer domain-age and newly-registered-domain controls to catch future short-lived C2 rotations; the campaign uses many ephemeral subdomains (lahuafa[.]com, ulbcl[.]com, siyangoil[.]com, ahroar[.]com, oukwww[.]com).
Weaknesses (CWE) in FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
CWE-506, CWE-829, CWE-601, CWE-922, CWE-494
Timeline of FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
- ESET publishes research on trojanized cryptocurrency wallet apps distributed via phishing sites abusing iOS provisioning profiles — the same delivery scheme FakeWallet now revives.
- Operator metadata embedded in FakeWallet samples (timestamps, log strings, config code reuse) indicates the campaign has been active since at least fall 2025, pre-dating public discovery.
- Kaspersky publishes research on the SparkKitty iOS trojan, which shares provisioning-profile abuse, phishing-page App-Store mimicry, Chinese-language artefacts, and crypto-theft objectives with FakeWallet.
- Kaspersky researchers observe a wave of phishing apps appearing at the top of Chinese App Store search results for major crypto wallets; investigation opens.
- Kaspersky identifies 26 phishing apps in the Apple App Store impersonating MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie, plus dormant clones with no active payload yet.
- Kaspersky reports the 26 phishing apps and associated IOCs to Apple; several apps begin to be removed from the App Store.
- Threadlinqs Intelligence ingests FakeWallet campaign as TL-2026-0395 and publishes IOC set, detection pack, and simulation plans.
- Securelist publishes the full technical deep-dive (author Sergey Puzan) including dylib injection, Objective-C hook chains, __hook section, React Native tamper, and complete IOC list.
- As of 2026-05-29, Apple removed all 26 FakeWallet App Store stubs after Kaspersky's Apr 2026 disclosure, but the campaign persists: its enterprise-profile/phishing-site delivery, C2 domains, and Android APKs are untouched, and the SparkKitty-linked Chinese-speaking actor stays active (SparkCat family resurfaced). No CVE, no arrests or sinkhole; vector contained but actor and tooling could resurge.
Sources cited for FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
- FakeWallet crypto stealer spreading through iOS apps in the App Store
- SparkKitty trojan research (Kaspersky)
- ESET — Trojanized wallets target phones (historical precursor, 2022)
- Apple Platform Security — Provisioning profile overview
- BIP-39 Mnemonic code for generating deterministic keys
- Ledger Live (open-source React Native source, abused as modification base)
- MITRE ATT&CK for Mobile — T1575 Native API (iOS hooking)
Threats related to FakeWallet iOS Crypto Stealer Campaign Delivered Through 26
Detection coverage for TL-2026-0395
As of 2026-04-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0395 across Splunk SPL, Microsoft KQL and Sigma, covering 56 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.