FakeWallet is a cryptocurrency-focused mobile malware campaign centered on trojanized wallet applications that impersonate legitimate crypto wallet brands in order to steal recovery phrases, private keys, and related wallet secrets. It has been identified on both Android and iOS, with notable activity involving fake wallet apps distributed through counterfeit websites and, in later activity, phishing applications placed in Apple’s App Store that redirected users to malicious installation flows. The operation has primarily targeted cryptocurrency users in China, exploiting the limited availability of some legitimate wallet applications in that market, but the malware’s functionality is not inherently region-locked.
On Android, FakeWallet has appeared as repackaged versions of legitimate wallet applications with malicious code inserted into wallet creation or import workflows so seed phrases can be captured and exfiltrated while the app retains expected wallet functionality. On iOS, observed variants have used multiple techniques, including malicious dynamic library injection, executable hooking, and direct modification of application source code, to intercept wallet restoration and recovery-phrase display flows. Some Ledger-focused variants relied on in-app phishing and fake verification screens rather than direct extraction, reflecting the different security model of cold-wallet companion applications.
The malware’s core objective is crypto-theft through credential and secret capture. Observed behaviors include scraping mnemonic phrases from wallet user interfaces, intercepting recovery workflows, collecting private keys, and exfiltrating stolen data to attacker-controlled infrastructure. Some variants encrypted captured mnemonics before transmission. Researchers have also documented fake wallet applications that simply solicit recovery phrases from victims without providing legitimate wallet functionality.
Distribution has relied on phishing-style impersonation of well-known wallet brands, typosquatting, fake promotional pages, counterfeit app-store experiences, and malicious or trojanized wallet installers. Earlier activity included dozens of fake websites promoting malicious Android and iOS wallet apps and affiliate-style recruitment of distributors. Later iOS-focused activity used benign-looking App Store stubs such as utility or game apps that redirected users to malicious pages and abused provisioning profiles to install infected wallet applications outside normal store controls.
FakeWallet is commonly classified by vendors as a mobile trojan or password-stealing trojan targeting cryptocurrency wallet secrets. Reporting has also noted possible overlap with SparkKitty in some iOS samples based on shared modules and tradecraft, although that linkage has been assessed rather than conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
...trick targets into downloading malicious wallet apps through iOS provisioning profiles, a technique evident in the SparkKitty campaign
This string is encrypted using RSA with the PKCS #1 scheme. The encrypted data is then encoded into Base64.
More than two dozen Apple App Store apps spoofing well-known cryptocurrency wallets Coinbase, Metamask, OneKey, and Trust Wallet, have been leveraged to pilfer seed phrases
Then the clearPendingMnemonicJob function replaces the contents of the file with an empty JSON dictionary.
In most cases, the malware is delivered via a malicious library injection... To embed the malicious library, the hackers injected load commands into the main executable... then swaps out legitimate class methods for malicious versions.
Included in the trojanized apps were additional code enabling the mnemonic phrase interception, encryption, and exfiltration.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android trojan family listed in detections appendix, associated by name with fake wallet applications.
Mentioned only as an Android trojan detection name in the appendix, likely referring to fake wallet malware.
A trojanized mobile cryptocurrency wallet threat affecting Android and iOS. Attackers repackage legitimate wallet apps such as Trust Wallet, Bitpie, OneKey, MetaMask, imToken, Coinbase Wallet, and TokenPocket, inject malicious code, and exfiltrate victims’ wallet seed phrases to attacker-controlled servers. Some variants transmit the seed phrase over unsecured HTTP.
A crypto-wallet trojan campaign distributed via phishing apps in the Apple App Store and phishing sites. It trojanizes legitimate wallet apps, injects malicious libraries or modifies app code, steals recovery phrases/private keys, encrypts the data, and exfiltrates it to attacker-controlled C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.