Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
October 8, 2026
Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
October 8, 2026
Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets
October 8, 2026
Home/CyberSecurity News/DarkSword iOS Exploit Steals Crypto Wallet Recovery Phrases via Coruna Malware
CyberSecurity News

DarkSword iOS Exploit Steals Crypto Wallet Recovery Phrases via Coruna Malware

Key Takeaways The DarkSword exploit platform, leveraging Coruna malware, is actively stealing cryptocurrency wallet recovery phrases from iPhones. Researchers uncovered exposed server infrastructure...

Jennifer sherman
Jennifer sherman
October 8, 2026 6 Min Read
2 0

Key Takeaways

  • The DarkSword exploit platform, leveraging Coruna malware, is actively stealing cryptocurrency wallet recovery phrases from iPhones.
  • Researchers uncovered exposed server infrastructure revealing the operational mechanics of this commercial theft service, including victim data and operator accounts.
  • The attack chain targets WebKit and JavaScriptCore vulnerabilities to achieve kernel access and inject wallet-specific theft modules into running applications.
  • Affected users include those with various popular crypto wallets on iOS devices, with at least 18 wallet applications targeted.
  • Patches for the underlying vulnerabilities have been released by Apple, but constant vigilance and system updates are crucial for defense.

DarkSword Exploits iOS to Harvest Crypto Wallet Seeds

A sophisticated threat actor group operating under the name DarkSword is employing Coruna malware to exfiltrate cryptocurrency wallet recovery phrases from compromised iPhones. This operation transcends typical browser exploits, functioning as a full-fledged theft-as-a-service platform.

Table Of Content

  • Key Takeaways
  • DarkSword Exploits iOS to Harvest Crypto Wallet Seeds
  • Discovery and Infrastructure Insights
  • The DarkSword-Coruna Attack Chain
  • A Reseller Platform with Active Devices
  • What You Should Do
  • Network and Infrastructure Indicators
  • Payload and Panel Hashes
  • Device, File, and Certificate Artifacts
  • Embedded Keys and Configuration Strings

An investigation into exposed server directories associated with the DarkSword/Coruna infrastructure has provided cybersecurity researchers with an unprecedented view into the platform’s inner workings. These directories contained wallet modules, command-and-control systems, and records of stolen data, offering a deeper understanding of the attack beyond its initial infection vector.

One production server instance contained alarming evidence: 11 victim recovery phrases, 179 distinct directories for device loot, and a list of 75 operator accounts. While these records do not confirm 179 individual victims or quantify the total value of stolen cryptocurrency, they strongly suggest a commercially driven operation complete with agents, commission structures, and device limitations.

Discovery and Infrastructure Insights

Researchers from Censys identified the compromised DarkSword/Coruna infrastructure between September 15 and September 17, 2026, through an internal scan for open directories. In their detailed report, published on October 7, Censys linked five previously undocumented hosts to various stages of the operation, including delivery, staging, analysis, and control systems. Disturbingly, some of this infrastructure remained active during the researchers’ analysis.

The DarkSword-Coruna Attack Chain

The DarkSword platform provides the initial access route into the target iOS device, while the Coruna malware delivers the specialized tools for wallet theft. Prior analysis of DarkSword exploits has detailed how the attack chain leverages vulnerabilities in WebKit and JavaScriptCore to break out of the browser sandbox and achieve kernel-level access. Once this critical access is established, the platform gains control over SpringBoard, the iOS process responsible for managing application launches and the user interface.

Following SpringBoard compromise, the platform deploys a three-tiered payload: an initial beacon, a second-stage controller, and a core implant. The SpringBoard coordinator continuously monitors for the launch of supported cryptocurrency wallet applications. Upon detection, it injects the corresponding theft module directly into the running wallet app. This injection process includes a rate limit, checking for app bundle injections no more frequently than once every three seconds.

The exposed kit reveals support for 18 different wallet modules, targeting popular applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie. Further analysis of the Coruna implant shows it also scans device photos and Apple Notes for BIP39 recovery phrases, validating them with checksums before exfiltration to filter out irrelevant text. Beyond credential theft, the implant can collect contacts, update itself, and retrieve daily configuration settings. Its wallet modules share a common AES encryption key, backup domain-generation settings, and utilize five data collection endpoints, imitating Safari traffic and bypassing TLS certificate checks.

A Reseller Platform with Active Devices

One of the exposed servers hosted a Python-based delivery service and a FastAPI administration panel, all backed by a database. This system registers new devices upon their first visit, serves landing pages for the exploit, collects exploit reports, and dispatches commands to active implants. The admin panel supports various features, including agent accounts, customizable commission rates, device quotas, and a library of over 60 commands. Separate logs indicated that two iPhones, running iOS 16.1 and 16.3.1, continuously checked a beacon page every three seconds for several hours on September 6, demonstrating active compromise.

While previous DarkSword infrastructure tracking focused on the rapid rotation of servers and web properties, these new findings illuminate the underlying software and organizational structure driving this malicious activity. It is important to note that some initial suspicions, such as files believed to contain stolen browser data, were later determined to be small test-device reports. However, the production server copy provided compelling evidence of wallet recovery phrase theft, although its exact origin remains unconfirmed, with researchers rejecting claims of it being part of an authorized red-team exercise.

In a separate discovery, Censys linked 22 samples from real-world infections to a distinct command server. Two of these samples specifically targeted BitKeep, expanding the list of affected wallets to 19. Certificate records tied this infrastructure to Tencent hosting and laboratory systems located in Shenyang, China. Researchers differentiated this operator from the exposed-directory cluster and have not publicly named either group.

Development files found referenced CVE-2026-31001, described as a JavaScriptCore type-confusion vulnerability aimed at iOS 26. However, companion sandbox and kernel stages were merely placeholders, indicating this was an unfinished project rather than a deployed iOS 26 attack. Similarly, an unverified claim of a CoreAudio zero-click vulnerability was noted in the operator registry but not confirmed on a live device.

Defenders are advised to prioritize all current iOS updates and actively monitor for server fingerprints and network indicators associated with this threat. Censys confirms that the vulnerabilities exploited in the established attack chains have been patched. Apple confirms that DarkSword fixes have been extended to more iOS 18 devices. Due to changing payload hashes, detection based solely on hashes may be insufficient; leveraging shared code signatures offers broader coverage against variants.

What You Should Do

  • Update iOS Immediately: Ensure all your Apple devices are running the latest iOS version to patch known vulnerabilities.
  • Use Hardware Wallets: For significant cryptocurrency holdings, consider moving funds to a hardware wallet, which offers a higher level of security against software exploits.
  • Be Wary of Links: Exercise extreme caution when clicking on suspicious links or visiting untrusted websites, as these are common initial vectors for browser exploits.
  • Monitor Wallet Activity: Regularly review your cryptocurrency wallet transaction history for any unauthorized activity.
  • Enable Multi-Factor Authentication (MFA): Where available, enable MFA on all cryptocurrency exchange accounts and wallet services.
  • Backup Recovery Phrases Securely: Store your recovery phrases offline and in a secure, encrypted manner, never digitally on your device or in cloud services.

Network and Infrastructure Indicators

All entries below come from the source report. Association with an operator’s lab or management system does not establish that a host served malware. Infrastructure status reflects the report’s observations, not a fresh availability check.

Type Indicator Role or context
IP:port 43.134.165[.]205:9999 DS-Fusion v1.0 distribution bundle
IP:port 166.88.95[.]90:9999 Operational command server with beacon telemetry
IP:port 23.148.212[.]237:8888 Operator analysis workspace; unfinished iOS 26 development
IP:port 47.102.192[.]23:9876 Coruna staging host
IP:ports 156.239.230[.]120:8080, 156.239.230[.]120:80 Exposed control platform and landing page
IP:port 185.189.45[.]40:8080 Earlier payload capture containing GHOST exploit stages
IP / domain 112.213.108[.]85 / hdios[.]cn Production server; hostname VM-NJb8T5qJl6
IP / domain 154.18.187[.]160 / fc.rsqqq[.]top Backup delivery stack; hostname SG-B20702-I
IP / domain 202.146.222[.]253 / i.131422[.]com Former production server; hostname C202609121655717
IP / domain 203.91.77[.]253 / st.onlinefc[.]top Operator work machine
IP:ports 154.217.250[.]206:80, 154.217.250[.]206:888 Suspected operator panel; moderate-confidence assessment
IP:port 14.128.47[.]81:443 Separate deployment of the group-named control panel
Domain ccwu[.]cc Parent domain of three panel-related subdomains; individual names not supplied
Domain wumian[.]cc.cd Panel-related hostname
C2 URL hxxps://66ds[.]lol Separate operator’s command server in 22 wild samples
Origin IP 101.35.158[.]183 Tencent-hosted origin behind the Cloudflare-fronted domain
Domain iplcz[.]cn Operator lab parent domain
Lab domains northlab[.]cn, g.northlab[.]cn, manager.g.northlab[.]cn Lab and management infrastructure; not identified as payload-serving hosts
Lab IPs 218.25.85[.]177, 218.25.85[.]178, 59.46.4[.]117, 59.46.4[.]119 Shenyang mail and lab infrastructure
Fallback C2 hxxp://199.30.90[.]154:18090 Hardcoded lab deployment host in the implant
Fallback pattern hxxps://backup%u[.]fit Wallet framework fallback replaced in wild builds
Operator contact @v66db Telegram sales contact on the landing page
Operator contact URL hxxps://t.me/YATA0000 Hidden contact link in the control panel
Historical campaign domains siekeltd[.]com, escofiringbijou[.]com Earlier DarkSword campaign indicators cited in the report’s references; not newly discovered cluster hosts

Payload and Panel Hashes

These values are reproduced exactly from the report. Censys did not label the algorithm of the 40-character shared module hash, so it is not presented as a confirmed SHA-1 value.

File or artifact Hash type Value
bootstrap.dylib SHA-256 c391bce7b09a0ea263e4b2c1d1bde0327c180723fa3299b006485429564c61ee
stage2.dylib SHA-256 8973e80ab494c02463d4123f76fc5e2dca2ea2c097317d246323d75c1f2eb791
core_v6.dylib SHA-256 a50c4da5c92636b2b1f170cdce3bd967a213886a8df5656cf3519214fcecfac5
core_a5.dylib SHA-256 54a4166ab33ffe02b41de9c943e783d20129b6cc22f56b7fe7d564fd02bde006
future-destroy.htm SHA-256 7ff5bb16cd5f8c92bc4fec72bba162662f202af075418db5000a1b4f81489fc2
Shared Coruna payload module Algorithm unspecified 1334417664270db20af705f422878c53c8378203
Control-panel page body Body hash, algorithm unspecified 864d68e64618d3bfc26d75d6f780ae0b7bfed3698cc8333818ed32519e560d1f

Device, File, and Certificate Artifacts

These artifacts can support investigation when found alongside other evidence; generic filenames or cookies alone should not be treated as proof of compromise.

Artifact type Value Context
LaunchDaemon path /Library/LaunchDaemons/com.apple.ds.agent.plist Device-side persistence
LaunchDaemon label com.apple.ds.agent Persistence service label
Command channel /tmp/nb_cmd Local interprocess command channel
Result channel /tmp/nb_result Local interprocess result channel
Cookies ds_uuid, ds_done, coruna-lab-session Device/session tracking
Wallet modules wallet01 through wallet18 Eighteen wallet theft modules
BitKeep module wallet19, libbitDylib.dylib, aware_retreat.css BitKeep identifiers and disguised module filename
Delivery artifacts group.html, exploit_server.py, darksword.db Landing page, delivery service, and control database
Telemetry files c2_results.jsonl, reports.jsonl Command results and device reports
Development files rce_worker_26.js, kernel_priv_26.js, vchain/ Unfinished iOS 26 work; not evidence of a deployed chain
Older delivery chain gooll/, gooll.html, entry1_type0x09.dylib Chain targeting older iOS versions
Delivery and variant artifacts /ios18/frame.html, manifest.json, daily_render.php, variants/set0 Version routing and changing payload builds
Certificate issuer Codex iOS Isolated Lab Root CA 2026 Private certificate authority linking the separate operator’s origin
Certificate organization IPLCZ Test Lab Certificate pivot used to identify the origin
Panel identifiers C2 Control Panel, C2 PANEL v3.0, 幽灵集团 Panel title, version banner, and group name

Embedded Keys and Configuration Strings

The following are malware configuration values published by Censys, not victim credentials.

Configuration artifact Exact value Purpose
AES key Ek8pl31K2yeHgQwy Shared data-transfer encryption
Wallet deployment seed UNDEFINED_DEPLOYMENT_SEED Domain generation
Wallet reporting seed UNDEFINED_REPORTING_SEED Domain generation
7z fallback password c73dfcfd60a0c7ebcc03352d433349bc Fallback transport configuration; not the build-time archive password
Plasma deployment seed 09d0b8d58a71653cd1c89c64c866f2e6 Deployment domain pool
Plasma reporting seed 2d2aebba0bf3d7d694194a7ab93b0a96 Reporting domain pool

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Teams Fights Deepfakes With AI-Powered Audio and Video Detection

Next Post

Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
October 8, 2026
Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us