FakeWallet crypto wallet phishing campaign targeting users in China
Campaign
Summary
Hide ▲
Show ▼
The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk of wallet takeover and asset theft. The operation uses fake branding and typosquatting to lure victims into downloading app-store listings disguised as games or calculator apps. Those lures redirect users to phishing pages and then to trojanized wallet installs. The same tradecraft is associated with SparkKitty, which has been running since last year.
Related Happenings
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
H score31
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware ActivityAbout this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
OkoBot hardware-wallet phrase theft campaign
Campaign
H score37
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
OkoBot hardware-wallet phrase theft campaign
CampaignAbout this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical Analysis
H score24
First: 14.07.2026 14:55
Last: 14.07.2026 14:55
Sources 1
About this happening:
KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical AnalysisAbout this happening: KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Trapdoor Android malvertising and ad-fraud campaign
Campaign
H score39
First: 19.05.2026 19:38
Last: 19.05.2026 19:38
Sources 1
About this happening:
The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...
Trapdoor Android malvertising and ad-fraud campaign
CampaignAbout this happening: The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...
Timeline
-
24.04.2026 14:48 1 articles · 2mo ago
FakeWallet linked to SparkKitty operators
Attribution UpdateKaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.
Show sources
- 26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — thehackernews.com — 24.04.2026 14:48
-
21.04.2026 00:52 1 articles · 2mo ago
Kaspersky identifies FakeWallet crypto wallet phishing campaign
Initial DisclosureKaspersky identified FakeWallet, a campaign of 26 malicious apps in the Apple App Store that impersonated Metamask, Coinbase, Trust Wallet, and OneKey to steal recovery or seed phrases and drain cryptocurrency assets. The apps targeted users in China, used typosquatting and fake branding, redirected victims to phishing pages, and abused iOS provisioning profiles to sideload trojanized wallet apps; Apple removed all 26 apps after Kaspersky’s responsible disclosure.
Show sources
- China's Apple App Store infiltrated by crypto-stealing wallet apps — www.bleepingcomputer.com — 21.04.2026 00:52