Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > DarkSword Exploit Service Uses Coruna Malware to Steal iPhone Wallet Recovery Phrases
DarkSword Exploit Service Uses Coruna Malware to Steal iPhone Wallet Recovery Phrases
Read Time:3 Minute, 28 Second

Operators of the DarkSword iOS exploit platform are using Coruna malware to steal cryptocurrency wallet recovery phrases from compromised iPhones, according to research based on exposed server infrastructure. The findings reveal more than an exploit chain: they show a commercial operation with delivery services, operator accounts, commissions, device limits, command systems, and specialized wallet-theft modules.

Censys researchers identified open directories tied to DarkSword and Coruna between September 15 and 17. Five previously undocumented hosts were linked to delivery, staging, analysis, or command activity. A copy of one production server held 11 recovery phrases, 179 device loot directories, and 75 operator accounts. Those artifacts demonstrate theft activity, but the directory count should not be treated as a confirmed victim total or an estimate of stolen funds.

Browser Exploitation Leads to Wallet Injection

DarkSword provides the initial route into an iPhone through a chain targeting WebKit and JavaScriptCore. The established attack flow escapes the browser sandbox, gains kernel-level access, and reaches SpringBoard, the iOS process responsible for app launches and the device interface. Coruna then supplies the components used to monitor and steal wallet data.

The platform loads a beacon, a second-stage controller, and a core implant. A SpringBoard coordinator watches for supported wallet applications to open and injects a matching theft module into the live process. The exposed kit contained 18 modules aimed at products including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie. Separate infection samples added evidence of a nineteenth target, BitKeep.

Coruna does not depend solely on in-app prompts. The implant searches photos and Apple Notes for BIP39 recovery phrases, checks candidates against the standard checksum, and sends only valid-looking phrases to its server. That filtering reduces noise and gives the operator material that may provide direct control of cryptocurrency assets. The malware can also collect contacts, refresh its settings, and update itself.

Exposed Panels Reveal an Exploit-for-Hire Business

One exposed host contained a Python delivery service and FastAPI administration panel backed by a database. The system registered devices on first contact, served landing pages, collected exploit reports, and relayed commands to implants. Its account features included commission rates, operator quotas, and more than 60 commands, consistent with a reseller or affiliate model rather than a single tightly controlled campaign.

Researchers observed two iPhones running iOS 16.1 and 16.3.1 repeatedly checking a beacon page. They also matched 22 infection samples from the wild to a separate command server. Infrastructure links pointed toward hosting and laboratory systems in Shenyang, China, but Censys distinguished that operator from the exposed-directory cluster and did not attribute either operation to a named group.

Development files referenced CVE-2026-31001 and an intended JavaScriptCore path for iOS 26. However, accompanying sandbox and kernel stages were placeholders. That material represents unfinished development, not evidence of a functioning iOS 26 compromise. A separate claim involving a CoreAudio zero-click route was also not verified on a device.

Updates and Behavior-Based Detection Matter

Censys says the established exploit chains have been patched, and Apple extended relevant fixes to additional iOS 18 devices. Users should install the latest iOS release available for their hardware, avoid opening unexpected links, and treat any exposed recovery phrase as permanently compromised. Funds should be moved to a newly generated wallet using a trusted, updated device; changing an app password cannot invalidate a stolen seed phrase.

  • Mobile security teams should monitor the published server fingerprints and network indicators.
  • Investigators should look for the reported LaunchDaemon persistence path and unusual SpringBoard injection behavior.
  • Wallet providers can hunt for shared module signatures, command channels, and anomalous recovery workflows.
  • Detection should combine behavior and infrastructure because payload hashes and delivery hosts can change quickly.

The exposed directories offer an unusually detailed view of how mobile exploitation is packaged for financially motivated operators. They also underline a central risk of cryptocurrency custody: once a recovery phrase is captured, the attacker no longer needs continued control of the phone. Rapid patching helps block entry, while careful phrase storage—offline and away from photos, notes, and cloud-synchronized text—limits what malware can steal after a device is breached.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on DarkSword Exploit Service Uses Coruna Malware to Steal iPhone Wallet Recovery Phrases, use the discussion on Forum.

>> forum community

Comments

Leave a Reply