Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sri Lanka to Launch 6G Research Centre by Q3 2026

    May 11, 2026

    Digital Education in Sri Lanka Needs More Than Smart Boards, Says PM

    May 9, 2026

    Safe “Sharenting” in APAC and Egypt

    May 9, 2026
    Facebook X (Twitter) LinkedIn
    Trending
    • Sri Lanka to Launch 6G Research Centre by Q3 2026
    • Digital Education in Sri Lanka Needs More Than Smart Boards, Says PM
    • Safe “Sharenting” in APAC and Egypt
    • HUTCH ENTERPRISE Unlocks World-Class Global Solutions to Level Up Sri Lankan Businesses
    • US and Sri Lanka Partner on AI Policy Framework for Higher Education
    • More than 50pct of leaked passwords end with a number, Kaspersky’s latest research reveals
    • Dialog Enterprise Expands Cybersecurity Leadership in Sri Lanka with AI-Powered Threat Detection Partnership with Seceon Inc
    • SINGER Introduces the New Apple MacBook Neo Series
    Facebook X (Twitter) LinkedIn
    Techie.LKTechie.LK
    Demo
    • Home
    • Local
      1. AI & Machine Learning
      2. Consumer Tech
      3. Cybersecurity
      4. Enterprise Tech
      5. Fintech & Digital Payments
      6. GovTech & e-Governance
      7. Legal & Regulatory Tech
      8. Science & Innovation
      9. Startups & Venture
      10. Telecom & Connectivity
      Featured

      Sri Lanka to Launch 6G Research Centre by Q3 2026

      By Techie.lkMay 11, 20260
      Recent

      Sri Lanka to Launch 6G Research Centre by Q3 2026

      May 11, 2026

      Digital Education in Sri Lanka Needs More Than Smart Boards, Says PM

      May 9, 2026

      HUTCH ENTERPRISE Unlocks World-Class Global Solutions to Level Up Sri Lankan Businesses

      May 9, 2026
    • International
      • AI & Machine Learning
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech & Digital Payments
      • GovTech & e-Governance
      • Legal & Regulatory Tech
      • Science & Innovation
      • Startups & Venture
      • Telecom & Connectivity
    • Interviews
    • Profiles
    • Analysis
    • Contributors
    • Podcasts
    • More
      • About Us
      • Contact Us
    Techie.LKTechie.LK
    Home»International»Kaspersky finds 26 fake crypto wallet apps on Apple’s App Store that can drain digital assets
    International

    Kaspersky finds 26 fake crypto wallet apps on Apple’s App Store that can drain digital assets

    Techie.lkBy Techie.lkApril 20, 2026Updated:April 23, 2026No Comments0 Views
    Facebook Twitter LinkedIn WhatsApp Reddit Tumblr Email
    1. (L-R) A phishing app mimicking Ledger on App Store, a web page imitating the App Store to download Ledger Wallet, and the victims allowing a developer profile to be installed on their device, which allows installing apps from outside the App Store including malicious apps
    (L-R) A phishing app mimicking Ledger on App Store, a web page imitating the App Store to download Ledger Wallet, and the victims allowing a developer profile to be installed on their device, which allows installing apps from outside the App Store including malicious apps
    Share
    Facebook Twitter LinkedIn

    Kaspersky Threat Research identified multiple fraudulent applications mimicking legitimate crypto wallets on the Apple App Store. Once opened, the apps redirect users to phishing pages which impersonate the App Store and deliver trojanized wallet applications capable of draining cryptocurrency holdings. Kaspersky determined the campaign has been active since at least fall 2025 and attributes it with moderate confidence to the threat actors behind SparkKitty.

    The 26 fraudulent applications Kaspersky identified each mimicked a popular crypto wallet, replicating icon visuals and using similar app names to deceive users: Metamask, Coinbase, Bitpie, Ledger, TokenPocket, Trust Wallet, and imToken.

    While official iOS apps for these cryptowallets are not available in the Chinese iOS App Store, almost all phishing applications that were detected were available only to Chinese iOS users. However, the malicious apps themselves have no regional restrictions, so victims outside China could also be affected. Kaspersky reported all malicious applications to Apple.

    1. (L-R) A phishing app mimicking Ledger on App Store, a web page imitating the App Store to download Ledger Wallet, and the victims allowing a developer profile to be installed on their device, which allows installing apps from outside the App Store including malicious apps
    (L-R) A phishing app mimicking Ledger on App Store, a web page imitating the App Store to download Ledger Wallet, and the victims allowing a developer profile to be installed on their device, which allows installing apps from outside the App Store including malicious apps

    These phishing apps feature stub functionality — such as games, calculators, to-do-list managers — that serve only to make the applications appear legitimate. When downloaded and launched, they subsequently open a webpage that imitates the App Store and invite users to download the desired “app” for managing crypto again.

    The installation process is similar to SparkKitty, the iOS malware Kaspersky described before – through special developer tools for distributing corporate business applications. The goal here is to confuse the user, as the attackers count on the users not paying attention and adding a developer profile to their device which then allows for a malicious app to be downloaded.

    As a result, a trojanized crypto wallet app gets installed. The malicious apps Kaspersky identified are each adapted to the specific wallet they impersonate and target both hot and cold wallets.

    A hot wallet stores private keys on the same internet-connected device where it is installed, making it convenient for frequent use but more vulnerable to attack. A cold wallet, by contrast, is a dedicated hardware device that keeps private keys entirely offline, trading some convenience for significantly stronger security. With hot wallets, the malware intercepts the wallet recovery/creation screen monitoring for seed phrases, and – if it is provided – the attackers get full access to victims’ funds.

    With cold wallets, the tactic is different. For instance, the Ledger crypto wallet service offers a frontend application which is the Ledger Wallet smartphone app, and a cold wallet on a separate hardware device that only signs transactions when physically connected or paired via Bluetooth to a smartphone with the Ledger Wallet app. The original Ledger wallet smartphone app would never ask for the seed phrase, as it is stored in the so called ‘cold’ wallet on a separate hardware device; however, the malicious app relies on phishing and tries to get the seed phrase from the user.

    “While the apps that kick off the attack chain are not inherently malicious, they lead to the user installing a trojan in the end. By paying a fee and setting up a developer account, the attackers can target any iOS device if the user succumbs to the phishing tactic. Users should be wary of the risks related to managing their crypto wallets even on devices that they consider safe, such as iPhones. We expect there may be more trojanized crypto apps distributed with a similar tactic,” comments Sergey Puzan, mobile malware expert at Kaspersky.

    Detailed information is available on Securelist.com. Kaspersky recommends the following to stay safe: Be cautious when following links from inside the apps, especially when a page appears unexpectedly. Do not install developer profiles unless provided to you by your employer. Make sure you fill in your recovery phrase only on your wallet device – for instance, the original Ledger Wallet app will never request it. Always check if the app you’re installing is from legitimate publisher – even when it’s downloaded from the App Store. It’s a good habit to check download links on official developer website.

    Share. Facebook Twitter LinkedIn
    Techie.lk
    • Website

    Related Posts

    Safe “Sharenting” in APAC and Egypt

    May 9, 2026

    More than 50pct of leaked passwords end with a number, Kaspersky’s latest research reveals

    May 8, 2026

    Kaspersky identified a new SilverFox campaign targeting Indian and Indonesian companies

    May 2, 2026
    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Sampath Bank and Apartner Bring Digital Payments to Sri Lanka’s Growing Condominium Sector

    March 16, 20268

    Sri Lanka’s USD 2.5 Million Cyber Fraud: Investigations Underway as Questions Emerge Over Payment Process

    April 23, 20266

    Moose Fan App gains significant traction throughout T20 World Cup

    March 12, 20266

    LankaPropertyWeb Unveils “Apartment Finder”: A Game-Changer in the Real Estate Market

    March 10, 20266
    Don't Miss
    Local

    Sri Lanka to Launch 6G Research Centre by Q3 2026

    By Techie.lkMay 11, 20260

    Sri Lanka is set to establish a dedicated research centre focused on 6G and next-generation…

    Digital Education in Sri Lanka Needs More Than Smart Boards, Says PM

    May 9, 2026

    Safe “Sharenting” in APAC and Egypt

    May 9, 2026

    HUTCH ENTERPRISE Unlocks World-Class Global Solutions to Level Up Sri Lankan Businesses

    May 9, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • LinkedIn

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    Your source for the lifestyle news. This demo is crafted specifically to exhibit the use of the theme as a lifestyle site. Visit our main page for more demos.

    We're accepting new partnerships right now.

    Email Us: techielkeditor@gmail.com
    Contact: +94 77 328 0773

    Facebook X (Twitter) LinkedIn
    Our Picks

    Sri Lanka to Launch 6G Research Centre by Q3 2026

    May 11, 2026

    Digital Education in Sri Lanka Needs More Than Smart Boards, Says PM

    May 9, 2026

    Safe “Sharenting” in APAC and Egypt

    May 9, 2026
    Most Popular

    Sampath Bank and Apartner Bring Digital Payments to Sri Lanka’s Growing Condominium Sector

    March 16, 20268

    Sri Lanka’s USD 2.5 Million Cyber Fraud: Investigations Underway as Questions Emerge Over Payment Process

    April 23, 20266

    Moose Fan App gains significant traction throughout T20 World Cup

    March 12, 20266
    © 2026 Techie. Designed by NIKO.
    • Terms & Conditions
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.