FakeWallet crypto stealer spreading in the App Store
· Published 20/04/2026 12:25 · Modified 20/04/2026 16:54
Essential information
- Published
- 20/04/2026 12:25
- Modified
- 20/04/2026 16:54
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- chinese targeting cryptocurrency enterprise certificates fakewallet ios phishing apps provisioning profiles sparkkitty app store credential theft cryptocurrency wallet
- Tags
- 2026-04-20 app store chinese targeting credential-theft cryptocurrency cryptocurrency wallet enterprise certificates fakewallet ios phishing apps provisioning profiles sparkkitty
- Related entities
- 53 indicators, 53 observables, 23 techniques (mitre), 2 malware, 22 others
Description
In March 2026, over twenty phishing applications were discovered in the Apple App Store masquerading as popular cryptocurrency wallets. These malicious apps redirect users to browser pages that distribute trojanized versions of legitimate wallets designed to steal recovery phrases and private keys. The campaign primarily targets users in China, exploiting regional restrictions that prevent official crypto wallet apps from being available in the Chinese App Store. Attackers use typosquatting and fake promotional materials to deceive users. The infected applications leverage iOS enterprise provisioning profiles for distribution and employ various techniques including malicious library injection and source code modification. The campaign has been active since at least fall 2025 and targets major wallets including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. Some infected apps also contained SparkKitty modules, suggesting potential links between threat actors.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Indicators (53)
-
https://appstoreios.com/DjZH?key=646556306F6Q465O313L737N3332939Y353I830F31 -
https://kkkhhhnnn.com/api/open/postByTokenpocket -
https://helllo2025.com/api/open/postByTokenpocket -
https://www.gxzhrc.cn/download/ -
crypto-stroe.cc -
https://api.npoint.io/153b165a59f8f7d7b097 -
https://nmu8n.com/tpocket/ios/Rsakeyword.php -
https://zdrhnmjjndu.ulbcl.com/tWe0ASmXJbDz3KGh?4a1bbe6d=31d25ddf2697b9e13ee883fff328b22f -
https://yjzhengruol.com/s/3f605f -
https://xz.apps-store.im/s/dDan?key=646756376F6A465D313L737J333993473233038L39&c= -
https://crypto-stroe.cc/ -
https://xz.apps-store.im/s/iuXt?key=646Y563Y6F6H465J313X737U333S9342323N030R34&c= -
https://ngy2yjq0otlj.ahroar.com/17pIWJfr9DBiXYrSb -
api.dc1637.xyz -
mti4ywy4.lahuafa.com -
nziwytu5n.lahuafa.com -
https://ngy2yjq0otlj.ahroar.com/EpCXMKDMx1roYGJ -
mtjln.siyangoil.com -
zdrhnmjjndu.ulbcl.com -
https://mtjln.siyangoil.com/08dT284P/1ZMz5Xmb0EoQZVvS5 -
https://ntm0mdkzymy3n.oukwww.com/7nhn7jvv5YieDe7P?0e7b9c78e=686989d97cf0d70346cbde2031207cbf -
ntm0mdkzymy3n.oukwww.com -
https://zmx6f.com/btp/ios/receiRsakeyword.php -
www.gxzhrc.cn -
iosfc.com -
https://139.180.139.209/prod-api/system/confData/getUserConfByKey/ -
https://xz.apps-store.im/CqDq?key=646R563V6F6Y465K313J737G343C3352383R336O35 -
https://mti4ywy4.lahuafa.com/UVB2U/mw2ZmvXKUEbzI0n -
https://mziyytm5ytk.ahroar.com/kAN2pIEaariFb8Yc -
https://odm0.siyangoil.com/TYTmtV8t/JG6T5nvM1AYqAcN -
mziyytm5ytk.ahroar.com -
helllo2025.com -
https://6688cf.jhxrpbgq.com/6axqkwuq -
https://ntm0mdkzymy3n.oukwww.com/jFms03nKTf7RIZN8?61f68b07f8=0565364633b5acdd24a498a6a9ab4eca -
https://iosfc.com/ledger/ios/Rsakeycatch.php -
kkkhhhnnn.com -
https://sxsfcc.com/api/open/postByTokenpocket -
https://api.dc1637.xyz -
nmu8n.com -
https://xz.apps-store.im/DjZH?key=646B563L6F6N4657313B737U3436335E3833331737 -
https://nziwytu5n.lahuafa.com/10RsW/mw2ZmvXKUEbzI0n -
xz.apps-store.im -
mgi1y.siyangoil.com -
https://zdrhnmjjndu.ulbcl.com/7uchSEp6DIEAqux?a3f65e=417ae7f384c49de8c672aec86d5a2860 -
sxsfcc.com -
ngy2yjq0otlj.ahroar.com -
odm0.siyangoil.com -
6688cf.jhxrpbgq.com -
zmx6f.com -
yjzhengruol.com -
appstoreios.com -
https://mgi1y.siyangoil.com/vmzLvi4Dh/1Dd0m4BmAuhVVCbzF -
ce5cb685b831d3eec4c86ca50b110827e7ad1f0e4fec41c4e4f87dcd97f262cb
Observables (53)
yjzhengruol.comiosfc.comhelllo2025.comsxsfcc.comkkkhhhnnn.comcrypto-stroe.ccappstoreios.comnmu8n.comzmx6f.commgi1y.siyangoil.comnziwytu5n.lahuafa.commti4ywy4.lahuafa.comzdrhnmjjndu.ulbcl.comxz.apps-store.immtjln.siyangoil.comwww.gxzhrc.cnngy2yjq0otlj.ahroar.comodm0.siyangoil.com6688cf.jhxrpbgq.comntm0mdkzymy3n.oukwww.commziyytm5ytk.ahroar.comapi.dc1637.xyzhttps://sxsfcc.com/api/open/postByTokenpockethttps://kkkhhhnnn.com/api/open/postByTokenpockethttps://xz.apps-store.im/CqDq?key=646R563V6F6Y465K313J737G343C3352383R336O35https://xz.apps-store.im/s/dDan?key=646756376F6A465D313L737J333993473233038L39&c=https://ngy2yjq0otlj.ahroar.com/EpCXMKDMx1roYGJhttps://zmx6f.com/btp/ios/receiRsakeyword.phphttps://odm0.siyangoil.com/TYTmtV8t/JG6T5nvM1AYqAcNhttps://xz.apps-store.im/DjZH?key=646B563L6F6N4657313B737U3436335E3833331737https://zdrhnmjjndu.ulbcl.com/7uchSEp6DIEAqux?a3f65e=417ae7f384c49de8c672aec86d5a2860https://mtjln.siyangoil.com/08dT284P/1ZMz5Xmb0EoQZVvS5https://ngy2yjq0otlj.ahroar.com/17pIWJfr9DBiXYrSbhttps://appstoreios.com/DjZH?key=646556306F6Q465O313L737N3332939Y353I830F31https://mgi1y.siyangoil.com/vmzLvi4Dh/1Dd0m4BmAuhVVCbzFhttps://mti4ywy4.lahuafa.com/UVB2U/mw2ZmvXKUEbzI0nhttps://helllo2025.com/api/open/postByTokenpockethttps://crypto-stroe.cc/https://zdrhnmjjndu.ulbcl.com/tWe0ASmXJbDz3KGh?4a1bbe6d=31d25ddf2697b9e13ee883fff328b22fhttps://www.gxzhrc.cn/download/https://139.180.139.209/prod-api/system/confData/getUserConfByKey/https://xz.apps-store.im/s/iuXt?key=646Y563Y6F6H465J313X737U333S9342323N030R34&c=https://iosfc.com/ledger/ios/Rsakeycatch.phphttps://nziwytu5n.lahuafa.com/10RsW/mw2ZmvXKUEbzI0nhttps://mziyytm5ytk.ahroar.com/kAN2pIEaariFb8Ychttps://api.npoint.io/153b165a59f8f7d7b097https://6688cf.jhxrpbgq.com/6axqkwuqhttps://ntm0mdkzymy3n.oukwww.com/jFms03nKTf7RIZN8?61f68b07f8=0565364633b5acdd24a498a6a9ab4ecahttps://nmu8n.com/tpocket/ios/Rsakeyword.phphttps://ntm0mdkzymy3n.oukwww.com/7nhn7jvv5YieDe7P?0e7b9c78e=686989d97cf0d70346cbde2031207cbfhttps://api.dc1637.xyzhttps://yjzhengruol.com/s/3f605fce5cb685b831d3eec4c86ca50b110827e7ad1f0e4fec41c4e4f87dcd97f262cb
Techniques (MITRE) (23)
-
Match Legitimate Resource Name or Location
-
Internal Spearphishing
-
Virtualization/Sandbox Evasion
-
File Deletion
-
Dynamic-link Library Injection
-
Steal Application Access Token
-
Process Injection
-
Encrypted Channel
-
Phishing
-
Web Protocols
-
Credentials from Password Stores
-
Native API
-
Obfuscated Files or Information
-
Invalid Code Signature
-
Steal Web Session Cookie
-
Standard Encoding
-
Deobfuscate/Decode Files or Information
-
GUI Input Capture
-
Input Capture
-
Masquerading
-
Subvert Trust Controls
-
Stage Capabilities
-
Exfiltration Over C2 Channel
Malware (2)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:06 · Modified 21/12/2025 15:06
-
FamilyPublished 20/04/2026 15:07 · Modified 20/04/2026 15:07
Others (22)
- China
- crypto-stroe.cc
- api.dc1637.xyz
- mti4ywy4.lahuafa.com
- nziwytu5n.lahuafa.com
- mtjln.siyangoil.com
- zdrhnmjjndu.ulbcl.com
- ntm0mdkzymy3n.oukwww.com
- iosfc.com
- mziyytm5ytk.ahroar.com
- helllo2025.com
- kkkhhhnnn.com
- nmu8n.com
- xz.apps-store.im
- mgi1y.siyangoil.com
- sxsfcc.com
- ngy2yjq0otlj.ahroar.com
- odm0.siyangoil.com
- 6688cf.jhxrpbgq.com
- zmx6f.com
- yjzhengruol.com
- appstoreios.com