DarkSword iOS Exploit Steals Crypto Wallet Recovery Phrases via Coruna Malware
Key Takeaways The DarkSword exploit platform, leveraging Coruna malware, is actively stealing cryptocurrency wallet recovery phrases from iPhones. Researchers uncovered exposed server infrastructure...
Key Takeaways
- The DarkSword exploit platform, leveraging Coruna malware, is actively stealing cryptocurrency wallet recovery phrases from iPhones.
- Researchers uncovered exposed server infrastructure revealing the operational mechanics of this commercial theft service, including victim data and operator accounts.
- The attack chain targets WebKit and JavaScriptCore vulnerabilities to achieve kernel access and inject wallet-specific theft modules into running applications.
- Affected users include those with various popular crypto wallets on iOS devices, with at least 18 wallet applications targeted.
- Patches for the underlying vulnerabilities have been released by Apple, but constant vigilance and system updates are crucial for defense.
DarkSword Exploits iOS to Harvest Crypto Wallet Seeds
A sophisticated threat actor group operating under the name DarkSword is employing Coruna malware to exfiltrate cryptocurrency wallet recovery phrases from compromised iPhones. This operation transcends typical browser exploits, functioning as a full-fledged theft-as-a-service platform.
Table Of Content
- Key Takeaways
- DarkSword Exploits iOS to Harvest Crypto Wallet Seeds
- Discovery and Infrastructure Insights
- The DarkSword-Coruna Attack Chain
- A Reseller Platform with Active Devices
- What You Should Do
- Network and Infrastructure Indicators
- Payload and Panel Hashes
- Device, File, and Certificate Artifacts
- Embedded Keys and Configuration Strings
An investigation into exposed server directories associated with the DarkSword/Coruna infrastructure has provided cybersecurity researchers with an unprecedented view into the platform’s inner workings. These directories contained wallet modules, command-and-control systems, and records of stolen data, offering a deeper understanding of the attack beyond its initial infection vector.
One production server instance contained alarming evidence: 11 victim recovery phrases, 179 distinct directories for device loot, and a list of 75 operator accounts. While these records do not confirm 179 individual victims or quantify the total value of stolen cryptocurrency, they strongly suggest a commercially driven operation complete with agents, commission structures, and device limitations.
Discovery and Infrastructure Insights
Researchers from Censys identified the compromised DarkSword/Coruna infrastructure between September 15 and September 17, 2026, through an internal scan for open directories. In their detailed report, published on October 7, Censys linked five previously undocumented hosts to various stages of the operation, including delivery, staging, analysis, and control systems. Disturbingly, some of this infrastructure remained active during the researchers’ analysis.
The DarkSword-Coruna Attack Chain
The DarkSword platform provides the initial access route into the target iOS device, while the Coruna malware delivers the specialized tools for wallet theft. Prior analysis of DarkSword exploits has detailed how the attack chain leverages vulnerabilities in WebKit and JavaScriptCore to break out of the browser sandbox and achieve kernel-level access. Once this critical access is established, the platform gains control over SpringBoard, the iOS process responsible for managing application launches and the user interface.
Following SpringBoard compromise, the platform deploys a three-tiered payload: an initial beacon, a second-stage controller, and a core implant. The SpringBoard coordinator continuously monitors for the launch of supported cryptocurrency wallet applications. Upon detection, it injects the corresponding theft module directly into the running wallet app. This injection process includes a rate limit, checking for app bundle injections no more frequently than once every three seconds.
The exposed kit reveals support for 18 different wallet modules, targeting popular applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie. Further analysis of the Coruna implant shows it also scans device photos and Apple Notes for BIP39 recovery phrases, validating them with checksums before exfiltration to filter out irrelevant text. Beyond credential theft, the implant can collect contacts, update itself, and retrieve daily configuration settings. Its wallet modules share a common AES encryption key, backup domain-generation settings, and utilize five data collection endpoints, imitating Safari traffic and bypassing TLS certificate checks.
A Reseller Platform with Active Devices
One of the exposed servers hosted a Python-based delivery service and a FastAPI administration panel, all backed by a database. This system registers new devices upon their first visit, serves landing pages for the exploit, collects exploit reports, and dispatches commands to active implants. The admin panel supports various features, including agent accounts, customizable commission rates, device quotas, and a library of over 60 commands. Separate logs indicated that two iPhones, running iOS 16.1 and 16.3.1, continuously checked a beacon page every three seconds for several hours on September 6, demonstrating active compromise.
While previous DarkSword infrastructure tracking focused on the rapid rotation of servers and web properties, these new findings illuminate the underlying software and organizational structure driving this malicious activity. It is important to note that some initial suspicions, such as files believed to contain stolen browser data, were later determined to be small test-device reports. However, the production server copy provided compelling evidence of wallet recovery phrase theft, although its exact origin remains unconfirmed, with researchers rejecting claims of it being part of an authorized red-team exercise.
In a separate discovery, Censys linked 22 samples from real-world infections to a distinct command server. Two of these samples specifically targeted BitKeep, expanding the list of affected wallets to 19. Certificate records tied this infrastructure to Tencent hosting and laboratory systems located in Shenyang, China. Researchers differentiated this operator from the exposed-directory cluster and have not publicly named either group.
Development files found referenced CVE-2026-31001, described as a JavaScriptCore type-confusion vulnerability aimed at iOS 26. However, companion sandbox and kernel stages were merely placeholders, indicating this was an unfinished project rather than a deployed iOS 26 attack. Similarly, an unverified claim of a CoreAudio zero-click vulnerability was noted in the operator registry but not confirmed on a live device.
Defenders are advised to prioritize all current iOS updates and actively monitor for server fingerprints and network indicators associated with this threat. Censys confirms that the vulnerabilities exploited in the established attack chains have been patched. Apple confirms that DarkSword fixes have been extended to more iOS 18 devices. Due to changing payload hashes, detection based solely on hashes may be insufficient; leveraging shared code signatures offers broader coverage against variants.
What You Should Do
- Update iOS Immediately: Ensure all your Apple devices are running the latest iOS version to patch known vulnerabilities.
- Use Hardware Wallets: For significant cryptocurrency holdings, consider moving funds to a hardware wallet, which offers a higher level of security against software exploits.
- Be Wary of Links: Exercise extreme caution when clicking on suspicious links or visiting untrusted websites, as these are common initial vectors for browser exploits.
- Monitor Wallet Activity: Regularly review your cryptocurrency wallet transaction history for any unauthorized activity.
- Enable Multi-Factor Authentication (MFA): Where available, enable MFA on all cryptocurrency exchange accounts and wallet services.
- Backup Recovery Phrases Securely: Store your recovery phrases offline and in a secure, encrypted manner, never digitally on your device or in cloud services.
Network and Infrastructure Indicators
All entries below come from the source report. Association with an operator’s lab or management system does not establish that a host served malware. Infrastructure status reflects the report’s observations, not a fresh availability check.
| Type | Indicator | Role or context |
|---|---|---|
| IP:port | 43.134.165[.]205:9999 |
DS-Fusion v1.0 distribution bundle |
| IP:port | 166.88.95[.]90:9999 |
Operational command server with beacon telemetry |
| IP:port | 23.148.212[.]237:8888 |
Operator analysis workspace; unfinished iOS 26 development |
| IP:port | 47.102.192[.]23:9876 |
Coruna staging host |
| IP:ports | 156.239.230[.]120:8080, 156.239.230[.]120:80 |
Exposed control platform and landing page |
| IP:port | 185.189.45[.]40:8080 |
Earlier payload capture containing GHOST exploit stages |
| IP / domain | 112.213.108[.]85 / hdios[.]cn |
Production server; hostname VM-NJb8T5qJl6 |
| IP / domain | 154.18.187[.]160 / fc.rsqqq[.]top |
Backup delivery stack; hostname SG-B20702-I |
| IP / domain | 202.146.222[.]253 / i.131422[.]com |
Former production server; hostname C202609121655717 |
| IP / domain | 203.91.77[.]253 / st.onlinefc[.]top |
Operator work machine |
| IP:ports | 154.217.250[.]206:80, 154.217.250[.]206:888 |
Suspected operator panel; moderate-confidence assessment |
| IP:port | 14.128.47[.]81:443 |
Separate deployment of the group-named control panel |
| Domain | ccwu[.]cc |
Parent domain of three panel-related subdomains; individual names not supplied |
| Domain | wumian[.]cc.cd |
Panel-related hostname |
| C2 URL | hxxps://66ds[.]lol |
Separate operator’s command server in 22 wild samples |
| Origin IP | 101.35.158[.]183 |
Tencent-hosted origin behind the Cloudflare-fronted domain |
| Domain | iplcz[.]cn |
Operator lab parent domain |
| Lab domains | northlab[.]cn, g.northlab[.]cn, manager.g.northlab[.]cn |
Lab and management infrastructure; not identified as payload-serving hosts |
| Lab IPs | 218.25.85[.]177, 218.25.85[.]178, 59.46.4[.]117, 59.46.4[.]119 |
Shenyang mail and lab infrastructure |
| Fallback C2 | hxxp://199.30.90[.]154:18090 |
Hardcoded lab deployment host in the implant |
| Fallback pattern | hxxps://backup%u[.]fit |
Wallet framework fallback replaced in wild builds |
| Operator contact | @v66db |
Telegram sales contact on the landing page |
| Operator contact URL | hxxps://t.me/YATA0000 |
Hidden contact link in the control panel |
| Historical campaign domains | siekeltd[.]com, escofiringbijou[.]com |
Earlier DarkSword campaign indicators cited in the report’s references; not newly discovered cluster hosts |
Payload and Panel Hashes
These values are reproduced exactly from the report. Censys did not label the algorithm of the 40-character shared module hash, so it is not presented as a confirmed SHA-1 value.
| File or artifact | Hash type | Value |
|---|---|---|
bootstrap.dylib |
SHA-256 | c391bce7b09a0ea263e4b2c1d1bde0327c180723fa3299b006485429564c61ee |
stage2.dylib |
SHA-256 | 8973e80ab494c02463d4123f76fc5e2dca2ea2c097317d246323d75c1f2eb791 |
core_v6.dylib |
SHA-256 | a50c4da5c92636b2b1f170cdce3bd967a213886a8df5656cf3519214fcecfac5 |
core_a5.dylib |
SHA-256 | 54a4166ab33ffe02b41de9c943e783d20129b6cc22f56b7fe7d564fd02bde006 |
future-destroy.htm |
SHA-256 | 7ff5bb16cd5f8c92bc4fec72bba162662f202af075418db5000a1b4f81489fc2 |
| Shared Coruna payload module | Algorithm unspecified | 1334417664270db20af705f422878c53c8378203 |
| Control-panel page body | Body hash, algorithm unspecified | 864d68e64618d3bfc26d75d6f780ae0b7bfed3698cc8333818ed32519e560d1f |
Device, File, and Certificate Artifacts
These artifacts can support investigation when found alongside other evidence; generic filenames or cookies alone should not be treated as proof of compromise.
| Artifact type | Value | Context |
|---|---|---|
| LaunchDaemon path | /Library/LaunchDaemons/com.apple.ds.agent.plist |
Device-side persistence |
| LaunchDaemon label | com.apple.ds.agent |
Persistence service label |
| Command channel | /tmp/nb_cmd |
Local interprocess command channel |
| Result channel | /tmp/nb_result |
Local interprocess result channel |
| Cookies | ds_uuid, ds_done, coruna-lab-session |
Device/session tracking |
| Wallet modules | wallet01 through wallet18 |
Eighteen wallet theft modules |
| BitKeep module | wallet19, libbitDylib.dylib, aware_retreat.css |
BitKeep identifiers and disguised module filename |
| Delivery artifacts | group.html, exploit_server.py, darksword.db |
Landing page, delivery service, and control database |
| Telemetry files | c2_results.jsonl, reports.jsonl |
Command results and device reports |
| Development files | rce_worker_26.js, kernel_priv_26.js, vchain/ |
Unfinished iOS 26 work; not evidence of a deployed chain |
| Older delivery chain | gooll/, gooll.html, entry1_type0x09.dylib |
Chain targeting older iOS versions |
| Delivery and variant artifacts | /ios18/frame.html, manifest.json, daily_render.php, variants/set0 |
Version routing and changing payload builds |
| Certificate issuer | Codex iOS Isolated Lab Root CA 2026 |
Private certificate authority linking the separate operator’s origin |
| Certificate organization | IPLCZ Test Lab |
Certificate pivot used to identify the origin |
| Panel identifiers | C2 Control Panel, C2 PANEL v3.0, 幽灵集团 |
Panel title, version banner, and group name |
Embedded Keys and Configuration Strings
The following are malware configuration values published by Censys, not victim credentials.
| Configuration artifact | Exact value | Purpose |
|---|---|---|
| AES key | Ek8pl31K2yeHgQwy |
Shared data-transfer encryption |
| Wallet deployment seed | UNDEFINED_DEPLOYMENT_SEED |
Domain generation |
| Wallet reporting seed | UNDEFINED_REPORTING_SEED |
Domain generation |
| 7z fallback password | c73dfcfd60a0c7ebcc03352d433349bc |
Fallback transport configuration; not the build-time archive password |
| Plasma deployment seed | 09d0b8d58a71653cd1c89c64c866f2e6 |
Deployment domain pool |
| Plasma reporting seed | 2d2aebba0bf3d7d694194a7ab93b0a96 |
Reporting domain pool |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.