
Security firm SlowMist reports Linux users face new threats as hackers revive expired domains to distribute backdoored crypto wallet apps via the Snap Store.
SlowMist’s Chief Information Security Officer 23pds has issued a warning about a recent Snap Store attack targeting Linux users. Hackers exploited expired developer domains to deliver malicious updates to applications imitating Exodus, Ledger Live, and Trust Wallet. These fake apps tricked users into entering their recovery phrases, enabling attackers to steal cryptocurrency holdings. The compromised domains were identified as storewise.tech and vagueentertainment.com.