Fake Ledger Live App on Apple Store Linked to $9.5M Crypto Theft

2026-04-15T20:51:46Z881537c96d52230cab99f2cd4d3d77d55ec35b07308d35b69aa40349fa3ec114
CVE-2026-5194app-store-fraudbotnetcrypto-theftdata-breachddosfileless-malwarehanghostinsider-threatiotloadermilitary-systemsransomwarerouterssupply-chain-riskviperTunnelvulnerabilitywolfssl

What happened

This feed reports multiple high-impact incidents: a fake Ledger Live app approved by Apple led to ~$9.5M in crypto theft from 50+ users; a 13.5M-device botnet is driving up to 2 Tbps DDoS attacks against fintech targets; an active HanGhost (HanGhost/Hanghost) loader campaign is conducting fileless, multi-stage malware delivery against payment and logistics workflows; ViperTunnel, a Python backdoor linked to DragonForce ransomware, is targeting Windows servers in the US/UK; Booking.com and Rockstar-related data exposures were reported (Rockstar leak reportedly no player PII); Kraken faces an on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
881537c96d52230cab99f2cd4d3d77d55ec35b07308d35b69aa40349fa3ec114
Enrichment time
2026-04-15T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.