Fake crypto wallet apps infiltrate apple App Store using legitimate tools

The campaign redirected iPhone users toward manipulated crypto wallet apps capable of stealing seed phrases and digital assets. Kaspersky identified 26 fraudulent applications imitating popular wallets such as MetaMask, Ledger and Trust Wallet.

 


Fake crypto wallet applications managed to enter Apple’s App Store using legitimate tools from the company’s developer ecosystem.

Kaspersky detected a campaign redirecting iPhone users toward manipulated versions capable of stealing digital assets.


A digital fraud campaign identified by Kaspersky managed to infiltrate Apple’s App Store through applications posing as legitimate cryptocurrency wallets. According to the company’s Threat Research team, the apps redirected users to fake pages imitating the official store in order to trick them into installing manipulated versions capable of taking control of digital assets.

The operation, active since at least late 2025, is believed to be linked to actors associated with SparkKitty, malware previously detected by Kaspersky on iOS devices. The campaign used legitimate Apple developer ecosystem tools to facilitate the installation of applications outside the official store.

Kaspersky identified 26 fraudulent applications replicating the names, icons and appearance of popular cryptocurrency wallets such as MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie.

Although the phishing applications targeted a specific audience, the company warned that any iPhone user could be affected because the malicious apps carried no geographic restrictions. Kaspersky said it reported the detected cases to Apple.

Fake applications on iPhone.

The applications included basic functions such as games, calculators or task lists to appear legitimate. However, once opened, they redirected users to a webpage imitating the App Store and invited them to download the supposed cryptocurrency wallet application again.

The mechanism followed a process similar to the one previously observed in SparkKitty for iOS. Instead of directly downloading a malicious application from the official store, users were guided toward installing a “developer profile” on the iPhone, a feature normally used for internal corporate applications.

Once that permission was accepted, the device became capable of installing external applications without additional warnings. In practice, this allowed attackers to distribute altered cryptocurrency wallet versions containing digital trojans designed to capture sensitive information and gain access to digital funds.

Attacks targeting crypto wallets.

The detected applications were adapted to the type of wallet they imitated and targeted both hot and cold wallets. A hot wallet stores private keys on an internet-connected device, making daily use easier but also increasing exposure to attacks. A cold wallet, by contrast, uses a separate hardware device to keep private keys offline.

In hot wallets, the malware intercepted wallet recovery or creation screens to monitor seed phrases and gain full access to victims’ funds.

In the case of cold wallets, the tactic relied on phishing. Kaspersky explained that services such as Ledger use separate hardware devices to store seed phrases and sign transactions only when the device is physically connected or paired via Bluetooth with the mobile application.

The legitimate Ledger smartphone application does not request seed phrases because that information remains stored on the physical device. Fraudulent versions, however, attempted to obtain those details directly from users in order to access the funds linked to the wallet.

Security recommendations.

María Isabel Manjarrez, security researcher at Kaspersky’s Global Research and Analysis Team, said:

“These applications do not appear dangerous at first, but they function as an entry point. The deception leads users step by step toward installing a fake app that ultimately becomes malware designed to steal their cryptocurrencies. What is concerning is that, by using legitimate Apple developer tools, attackers can deliver these types of scams to any iPhone if the person falls into the trap. That is why, even on devices considered secure, it is essential to remain alert to any unusual installation process. We are likely to see more cases like this using similar tactics.”

The company recommended avoiding unexpected links inside applications, not installing unknown profiles or permissions and always verifying the official developer before downloading any cryptocurrency-related app.

It also advised reviewing user comments and ratings and using security solutions capable of detecting fake webpages and fraud attempts.


Share:
Hosting Web
Most Read