Fake Ledger Live App on Apple Store Linked to $9.5M Crypto Theft
2026-04-15T20:51:46Z•881537c96d52230cab99f2cd4d3d77d55ec35b07308d35b69aa40349fa3ec114
CVE-2026-5194app-store-fraudbotnetcrypto-theftdata-breachddosfileless-malwarehanghostinsider-threatiotloadermilitary-systemsransomwarerouterssupply-chain-riskviperTunnelvulnerabilitywolfssl
What happened
This feed reports multiple high-impact incidents: a fake Ledger Live app approved by Apple led to ~$9.5M in crypto theft from 50+ users; a 13.5M-device botnet is driving up to 2 Tbps DDoS attacks against fintech targets; an active HanGhost (HanGhost/Hanghost) loader campaign is conducting fileless, multi-stage malware delivery against payment and logistics workflows; ViperTunnel, a Python backdoor linked to DragonForce ransomware, is targeting Windows servers in the US/UK; Booking.com and Rockstar-related data exposures were reported (Rockstar leak reportedly no player PII); Kraken faces an on
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 881537c96d52230cab99f2cd4d3d77d55ec35b07308d35b69aa40349fa3ec114
- Enrichment time
- 2026-04-15T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.