SeaFlower is a previously unreported malware campaign/activity cluster targeting Web3 cryptocurrency wallet users by distributing trojanized mobile wallet applications that preserve normal wallet functionality while covertly stealing wallet secrets. Reported targets include MetaMask, Coinbase Wallet, imToken, and TokenPocket on both iOS and Android. The operation used cloned wallet download sites and commonly acquired victims via Chinese search engines, with iOS victims installing apps through provisioning profiles outside the App Store and Android victims downloading APKs directly.
The malware’s core behavior is seed phrase theft and fund-draining enablement. On iOS, analyzed samples used injected dynamic libraries, Objective-C hooking via Logos/MSHookMessageEx, and React Native bundle tampering/loading to capture mnemonic phrases and related wallet data. In the MetaMask iOS case, an RSA-encrypted Base64 blob was decrypted at runtime to recover a missing startupload() function that sent a POST request to trx.lnfura.org and exfiltrated the seed phrase stored in xlmnmonic. Reporting also states SeaFlower exfiltrated seed phrases, wallet addresses, and balances over HTTPS to attacker-controlled lookalike domains. Additional iOS samples included injected dylibs such as libWalletDylib.dylib, libimtokenhookDylib.dylib, and libpocketDylib.dylib, with hooks placed on wallet-related methods including setMnemonic: and React Native loading paths.
On Android, the reported Coinbase Wallet sample used smali-injected code in a class named XMPMetadata and triggered exfiltration when the seed phrase was saved to storage in saveMnemonicToStorage(). The Android C2 URL was Base64-encoded as aHR0cHM6Ly9jb2xuYmFzZS5ob21lcy91L3Ntcy8=, decoding to https://colnbase.homes/u/sms/.
Observed infrastructure and lures included cloned sites such as som-coinbase.com, appim.xyz, 74871011.huliqianbao.com/download.html, and fastrpo.com, as well as attacker-controlled domains including trx.lnfura.org, colnbase.homes, and metanask.cc. The campaign was assessed as highly sophisticated, especially on iOS, and multiple artifacts in the reporting linked it to Chinese-speaking operators, including Chinese-language comments, leaked developer usernames, and infrastructure in Chinese/Hong Kong IP space. High-confidence indicators explicitly mentioned in the content include SHA-256 hashes 9003d11f9ccfe17527ed6b35f5fe33d28e76d97e2906c2dbef11d368de2a75f8 (MetaMask iOS), 2334e9fc13b6fe12a6dd92f8bd65467cf700f43fdb713a209a74174fdaabd2e2 (Coinbase Wallet iOS), 1e232c74082e4d72c86e44f1399643ffb6f7836805c9ba4b4235fedbeeb8bdca (imToken iOS), 46002ac5a0caaa2617371bddbdbc7eca74cd9cb48878da0d3218a78d5be7a53a (TokenPocket iOS), and 83dec763560049965b524932dabc6bd6252c7ca2ce9016f47c397293c6cd17a5 (Coinbase Wallet Android).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"SeaFlower is a cluster of activity ... targeting web3 wallet users" ... "modify web3 wallets with backdoor code that ultimately exfiltrates the seed phrase."
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SeaFlower is a trojanized mobile-app backdoor campaign targeting Web3 wallet users by distributing pixel-perfect cloned iOS/Android wallet apps. On iOS it injects malicious .dylib libraries (using tools like Cydia Substrate/Cycript/MonkeyDev) to hook runtime behavior, decrypt an RSA-protected payload at runtime, and exfiltrate seed phrases, wallet addresses, and balances over HTTPS to attacker-controlled lookalike domains. On Android it injects malicious smali code to POST seed phrases when saved, with C2 domains obfuscated (e.g., Base64).
A campaign/tooling set that distributes trojanized (backdoored) mobile Web3 wallet apps (iOS/Android) by modifying legitimate wallets and adding code to exfiltrate victims’ seed phrases (mnemonics), wallet addresses, and balances to attacker-controlled domains over HTTPS. On iOS it uses injected/sideloaded dylibs, hooking frameworks (e.g., Cydia Substrate/Logos/MonkeyDev) and encrypted React Native bundle injection; on Android it injects code (e.g., smali) to steal the mnemonic when saved.
A backdoor campaign targeting trojanized mobile Web3 wallet applications on iOS and Android. It captures wallet seed phrases/mnemonics and exfiltrates them to attacker-controlled domains, including via injected dylibs, React Native bundle hooks, and Android smali/class modifications.
SeaFlower is a sophisticated backdoor campaign targeting web3 wallet users, specifically by distributing trojanized versions of popular iOS and Android cryptocurrency wallets (MetaMask, Coinbase Wallet, TokenPocket, imToken). The malware injects backdoor code into legitimate wallet apps, exfiltrating seed phrases, wallet addresses, and private keys to attacker-controlled infrastructure. Distribution is primarily via fake/cloned wallet websites, often reached through search engine poisoning, especially on Chinese search engines. The campaign is notable for its technical sophistication, use of iOS provisioning profiles, and focus on the web3/crypto sector.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.