A hand holding a smartphone displaying Apple Inc. (AAPL) stock with buy and sell options, with a stock chart visible on a monitor in the background.
TECHNOLOGY

SlowMist Has Not Confirmed Safari Crypto Theft

Image Credit: Shutterstock

SlowMist has not confirmed cryptocurrency theft caused by the Safari-based iPhone  attack behind recent warnings that malicious webpages could expose private keys and seed phrases. The security firm found code capable of reaching Apple Keychain data, files belonging to other apps and keyboard input. 

Its Sept. 4 analysis was based on static evidence rather than successful exploitation of a victim device, and SlowMist cautioned that visiting the malicious page alone does not prove wallet credentials were stolen.

Safari Page Can Launch Exploit Without Another Click

SlowMist analyzed a campaign disguised as a free virtual private server service. The malicious event[.]polarnode[.]vip page automatically loaded its attack script after becoming interactive without requiring another click.

The confirmed loader targeted iPhones using Safari on iOS 18.4 through 18.6.2. It could launch a multi-stage chain involving browser exploitation, two sandbox escapes and kernel privilege escalation.

Post-exploitation code included functions for collecting application files, decrypting Keychain records and monitoring keyboard input when imToken, TokenPocket or TronLink was open. SlowMist said those capabilities existed in the code but did not establish that they had successfully executed on a real victim device.

SlowMist Analysis Confirms iOS 18.4-to-18.6.2 Chain

A separate Sept. 19 warning from SlowMist CISO 23pds cited a broader potential attack range from iOS 13 through iOS 26.5.

That wider range has not been demonstrated in SlowMist’s published Sept. 4 technical analysis. The complete Safari chain examined there covers iOS 18.4 through 18.6.2, while an additional branch targeting some older versions could not be retrieved for analysis.

The analyzed chain closely matches DarkSword, an exploit framework Google documented in March as supporting iOS 18.4 through 18.7. Google said the six-vulnerability chain had been used by multiple threat actors before Apple patched the underlying flaws.

FomoPeek Theft Remains a Separate iOS Attack

The Safari campaign is separate from FomoPeek, the malicious App Store application SlowMist recently linked to reported crypto thefts.

FomoPeek versions 1.1 and 1.2 contained malicious modules capable of kernel exploitation, sandbox escape, Keychain decryption and cross-app data collection. SlowMist traced 579,984.34 USDT to a primary attacker address associated with that separate investigation.

SlowMist has not established the same victim-loss connection for the Safari sample. It recommends installing current iOS security updates and using device forensics before concluding that exposed wallets or credentials were compromised.

More For You

Explore More News