Find notable cyber news and cases, enriched with sources, timelines, and signals.

FakeWallet crypto wallet phishing campaign targeting users in China

Campaign
First reported
Last updated
Happening score
H score 14
2 unique sources, 2 articles

Summary

Hide ▲

The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk of wallet takeover and asset theft. The operation uses fake branding and typosquatting to lure victims into downloading app-store listings disguised as games or calculator apps. Those lures redirect users to phishing pages and then to trojanized wallet installs. The same tradecraft is associated with SparkKitty, which has been running since last year.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...

OkoBot hardware-wallet phrase theft campaign

Campaign
H score37 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: An active OkoBot campaign is driving hundreds of victimizations across more than 25 countries, showing broad coordinated malware activity. The operation uses overlapping d...

KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking

Technical Analysis
H score24 First: 14.07.2026 14:55 Last: 14.07.2026 14:55 Sources 1

About this happening: KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Trapdoor Android malvertising and ad-fraud campaign

Campaign
H score39 First: 19.05.2026 19:38 Last: 19.05.2026 19:38 Sources 1

About this happening: The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...

Timeline

  1. 24.04.2026 14:48 1 articles · 2mo ago

    FakeWallet linked to SparkKitty operators

    Attribution Update

    Kaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.

    Show sources
  2. 21.04.2026 00:52 1 articles · 2mo ago

    Kaspersky identifies FakeWallet crypto wallet phishing campaign

    Initial Disclosure

    Kaspersky identified FakeWallet, a campaign of 26 malicious apps in the Apple App Store that impersonated Metamask, Coinbase, Trust Wallet, and OneKey to steal recovery or seed phrases and drain cryptocurrency assets. The apps targeted users in China, used typosquatting and fake branding, redirected victims to phishing pages, and abused iOS provisioning profiles to sideload trojanized wallet apps; Apple removed all 26 apps after Kaspersky’s responsible disclosure.

    Show sources