SlowMist Security Researcher Reveals Crypto Phishing Attack Exploiting Apple Device 2FA

Share This Post

A recent revelation by a SlowMist security researcher has highlighted a new type of attack aimed at cryptocurrency holders using Apple devices. The researcher disclosed that a malicious phishing program has been detected on the Apple App Store which he described as the newest form of attack targeting Apple IDs.

Cryptocurrency users have been warned to be particularly cautious as many of them rely on iCloud to back up their wallets. This is because, in the event of an attack, their assets could be at risk of loss if their 2FA gets compromised.

The malicious phishing program is able to do this by replicating normal applications. And subsequently, the attacker adds their own number to the trusted two-factor authentication list, thereby gaining control over the account permissions.

Related Reading: South Korean Private Banks Explore Alternatives To Private Stablecoins And CBDCs

Phishing stands as a significant threat among numerous crypto scams, posing a considerable danger to the entire cryptocurrency community. In phishing attacks, malicious actors employ deceptive techniques to trick users into revealing sensitive information, such as private keys, passwords, or seed phrases, with the aim of gaining unauthorized access to their cryptocurrency wallets and funds

Vulnerabilities Found In iOS And MacOS Platforms

Online forum users have also reported experiencing phishing attempts despite having 2FA in place. Additionally, cybersecurity firm Kaspersky identified vulnerabilities in the iOS and macOS platforms, posing a risk of crypto asset loss.

These security flaws enable attackers to obtain user details and root privileges, which SlowMist later verified that the identified vulnerabilities were present in both operating systems.

Both SlowMist and Kaspersky have now urged users to update their iOS and macOS devices to safeguard against these potential risks. This warning is coming shortly after Kaspersky’s disclosure that crypto phishing attacks surged by 40% year-over-year from 2022 to 2021, indicating a higher risk of being compromised for crypto users.

MetaMask Issued Prior Warning On Crypto Phishing Scams

SlowMist and Kaspersky are not the only ones that have issued warnings about phishing scams as MetaMask issued a prior warning about the potential use of Apple iCloud backups as a phishing tool. This cautionary message followed a reported incident where an Apple user allegedly lost $650,000 worth of digital assets from their MetaMask wallet.

In April 2023, the wallet provider alerted Apple users about the risk associated with automatic iCloud backups of their MetaMask wallet data, specifically highlighting that it could lead to their seed phrases being stored online.

To access the wallet, one requires a ‘seed phrase,’ which essentially functions as the password and one of the essential precautions is setting a strong and secure password.

Metamask’s warning notified users who hadn’t modified their default device settings that they might risk losing their funds if they failed to implement essential security measures.

Crypto

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitcoin Price Could Enter ‘Period Of Positive Seasonal Performance’ — But This Needs To Happen

The Bitcoin price having an outstanding Q4 to close the year 2024 has been one of the most prominent narratives in the cryptocurrency market in recent weeks Interestingly, a popular blockchain firm

Zimbabwe Injects $50 Million to Bolster Devalued Currency

The Reserve Bank of Zimbabwe (RBZ) has injected an additional $50 million into the market to support the foreign exchange system However, industry leaders believe the bank is not doing enough to

Shiba Inu Burn Rate Shoots Up 1,000% – Are New ATH Levels Just Around The Corner?

Shiba Inu is making waves after wrapping up an astounding 1,000% increase in its burn rate, Shibburn data shows This has occurred simultaneously with a nearly 7% increase in the value of the meme

Nigeria Introduces System to Boost Forex Market Transparency

The Central Bank of Nigeria (CBN) is launching a new electronic system (EFEMS) to improve transparency in the foreign exchange market This comes as the Nigerian currency weakens Authorized dealers

Building Web3 culture in Ukraine: Rostyslav Bortman’s mission

Rostyslav Bortman is Head of Blockchain Development at IdeaSoft and founder of ETHKyiv Community He is one of the main faces of the global and Ukrainian Web3 development and a driving force behind

DC Circuit Court Rules Kalshi’s US Election Bets Legal

This week, the US Court of Appeals for the District of Columbia Circuit has ruled in favor of the predictions market Kalshi, allowing the commodities exchange to offer event contracts based on the