MarsBit: "ComeCome" App Suspected of Bundling Malicious SDK in Attack Resembling FomoPeek Case

AI مارکیٹ کا خلاصہ
SlowMist's founder reported ComeCome (comecome.icu) using an attack pattern similar to the FomoPeek incident, embedding a malicious SDK that leverages multiple iOS kernel exploit techniques (reported affected versions spanning iOS 12–18.7) to bypass sandbox protections and steal crypto wallet assets. The disclosure heightens operational risk for retail users, potentially dampening near-term on-chain activity and sentiment, while increasing scrutiny of mobile wallet security and app-source hygiene.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.42%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Huo Xing Cai Jing reported that Yu Xian, founder of cybersecurity firm SlowMist, said a new app dubbed ComeCome (comecome.icu) has been flagged for using tactics similar to those seen in the recent FomoPeek app poisoning and theft incident. ComeCome is presented as a food delivery app. According to Yu, FomoPeek versions v1.1–1.2 embedded a malicious SDK that incorporated eight iOS kernel exploit techniques and automatically chose an attack path based on the device model and operating system version. The exploits are known to affect iOS versions ranging from iOS 12–18.7 and 26–26.1. Once exploitation succeeds, the attacker can bypass iOS sandbox protections to steal assets from cryptocurrency wallets. Yu cautioned that the threat could also extend to iPad and Mac devices, urging users to update to the latest iOS version and to treat apps from untrusted sources with extreme caution.