DarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases
DarkSword's Coruna malware uses iOS browser exploits to steal cryptocurrency wallet recovery phrases from iPhones.
Censys reported that DarkSword operators use Coruna malware to steal cryptocurrency wallet recovery phrases from iPhones after a WebKit and JavaScriptCore exploit escapes the browser sandbox, gains kernel access, and reaches SpringBoard. The implant injects modules into apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie, and scans Photos and Apple Notes for valid BIP39 phrases. An exposed production copy held 11 recovery phrases, 179 device loot directories, and 75 operator accounts; Censys also matched 22 in-the-wild samples to a separate server. Referenced bug CVE-2026-31001 was unfinished placeholder work, not a deployed iOS 26 attack, and Apple says the established chains are patched.