Digital Wallet
By Sakamoto Nashi
1 / 15
How the Fake Apps Work. The fraudulent apps don't look suspicious at first. They offer random features like games and…
2 / 15
Counterfeit Hardware Devices Join the Mix. A fake Ledger Nano S Plus device turned up in a separate phishing operation.
3 / 15
Kaspersky just caught 26 fake cryptocurrency wallet apps on Apple's App Store. These things were built to drain digital assets from users who thought they were downloading the…
4 / 15
The scam apps pretend to be MetaMask, Ledger, and Coinbase wallets. Users install what looks like a legit app, then get pushed to phishing pages that look exactly like the App…
5 / 15
The fraudulent apps don't look suspicious at first. They offer random features like games and calculators to pass Apple's initial review process. Pretty clever, actually.
6 / 15
Installing that profile lets the app pull in software from outside the App Store. Apple's normal security checks don't catch it.
7 / 15
Cyber attackers found a way to exploit Apple's enterprise developer tools. These tools were meant for companies to distribute internal apps to employees.
8 / 15
The scam works because many official versions of popular wallet apps aren't available in the Chinese iOS App Store. That gap creates demand, and the fake apps fill it.
9 / 15
A fake Ledger Nano S Plus device turned up in a separate phishing operation. Someone bought it through an online marketplace, and it looked totally genuine at first glance.
10 / 15
A Brazilian researcher took the thing apart and found mismatched components inside. The device had extra WiFi and Bluetooth antennas that shouldn't be there.
11 / 15
Read also: HackerOne Logs 85,000 Valid Bug Reports in 2025 as AI Tools Flood Platforms
12 / 15
This attack didn't exploit any vulnerability in Ledger's actual security system. It relied on fake hardware and phishing to compromise users.
13 / 15
When the fake Ledger connected to Ledger Live, it immediately failed verification. That's when the owner knew something was wrong.
14 / 15
The fake apps on the App Store used a similar deception tactic. They included basic features that made them seem harmless.
15 / 15
Users thought they were downloading the wallet app they wanted. Instead, they got a trojanized version that immediately started working to steal their funds.
The Currency Analytics
Want the full story?