DarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases
DarkSword's Coruna malware uses iOS browser exploits to steal cryptocurrency wallet recovery phrases from iPhones.
Censys reported that DarkSword operators use Coruna malware to steal cryptocurrency wallet recovery phrases from iPhones after a WebKit and JavaScriptCore exploit escapes the browser sandbox, gains kernel access, and reaches SpringBoard. The implant injects modules into apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie, and scans Photos and Apple Notes for valid BIP39 phrases. An exposed production copy held 11 recovery phrases, 179 device loot directories, and 75 operator accounts; Censys also matched 22 in-the-wild samples to a separate server. Referenced bug CVE-2026-31001 was unfinished placeholder work, not a deployed iOS 26 attack, and Apple says the established chains are patched.
- WebKit and JavaScriptCore exploit chain reaches SpringBoard after kernel access.
- Wallet modules target MetaMask, Phantom, Trust Wallet, Coinbase, and others.
- Exposed server held 11 recovery phrases and 75 operator accounts.
- Censys matched 22 in-the-wild samples to a separate command server.
- CVE-2026-31001 was unfinished and not a deployed iOS 26 attack.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-31001 | NVD description · AI analysis pending | — | — | — | — | — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 131422.com | ack; hostname SG-B20702-I IP / domain 202.146.222[.]253 / i.131422[.]com Former production server; hostname C202609121655717 IP / |
| domain | 66ds.lol | Domain wumian[.]cc.cd Panel-related hostname C2 URL hxxps://66ds[.]lol Separate operator’s command server in 22 wild samples Ori |
| domain | ccwu.cc | Separate deployment of the group-named control panel Domain ccwu[.]cc Parent domain of three panel-related subdomains; individu |
| domain | escofiringbijou.com | control panel Historical campaign domains siekeltd[.]com , escofiringbijou[.]com Earlier DarkSword campaign indicators cited in the report |
| domain | hdios.cn | taining GHOST exploit stages IP / domain 112.213.108[.]85 / hdios[.]cn Production server; hostname VM-NJb8T5qJl6 IP / domain 154 |
| domain | iplcz.cn | t-hosted origin behind the Cloudflare-fronted domain Domain iplcz[.]cn Operator lab parent domain Lab domains northlab[.]cn , g. |
| domain | northlab.cn |
Full article1,392 words · extracted from cybersecuritynews.com · click to collapse
DarkSword operators are using Coruna malware to steal cryptocurrency wallet recovery phrases from iPhones, turning browser exploits into a ready-to-use theft service.
Exposed server directories revealed wallet modules, command systems, and records of stolen data, giving researchers a closer look at how the platform works beyond its initial exploit chain.
A copy of one production server contained 11 victim recovery phrases, 179 device loot directories, and a roster of 75 operator accounts.
Those records point to a commercial operation with agents, commissions, and device limits. They do not establish 179 confirmed victims or show the total value of stolen cryptocurrency.
Researchers from Censys identified the exposed DarkSword/Coruna infrastructure through an internal index of open directories between September 15 and September 17, 2026.
In its October 7 report, the company linked five previously undocumented hosts to delivery, staging, analysis, and control systems. Some infrastructure remained active when researchers examined it.
DarkSword iOS Exploit Platform Uses Coruna Malware
DarkSword supplies the route into the device, while Coruna supplies the wallet theft tools. Earlier DarkSword exploit coverage explains how the chain attacks WebKit and JavaScriptCore, breaks out of the browser sandbox, and gains kernel access.
It then reaches SpringBoard, the iOS process that controls app launches and the screen. After that access is gained, the platform loads three main layers: a starting beacon, a second-stage controller, and a core implant.
The SpringBoard coordinator watches for supported wallet apps to open, then injects the matching theft module into the running app. Its injection checks are limited to one per three seconds for each app bundle.
The exposed kit contains 18 wallet modules targeting apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie.
.webp)
Previous Coruna exploit analysis describes the wider toolkit behind this theft model. The newly examined implant also searches photos and Apple Notes for BIP39 recovery phrases, sending only phrases that pass checksum checks.
That checking step helps filter out random text before stolen material reaches the server. The implant can also collect contacts, update itself, and fetch daily settings.
Its wallet modules share an AES encryption key, backup domain-generation settings, and five data collection endpoints. They imitate Safari traffic and disable TLS certificate checks.
A Reseller Platform With Active Devices
One exposed server contained a Python delivery service and a FastAPI admin panel backed by a database. The service registers devices on their first visit, serves landing pages, collects exploit reports, and passes commands to implants.
The panel supports agent accounts, commission rates, device quotas, and more than 60 allowed commands. Separate logs showed two iPhones checking a beacon page every three seconds for hours on September 6. They ran iOS 16.1 and 16.3.1.
Earlier DarkSword infrastructure tracking documented rapidly changing servers and web properties; the latest findings expose the software and account structure behind that activity rather than just its public pages.
The evidence needs careful reading. Files first suspected of holding stolen browser data on one host proved to be small test-device reports.
The production-server copy provided stronger evidence of wallet recovery-phrase theft, but Censys said its origin was unknown. Researchers rejected its claim that it came from an authorized red-team exercise.
Censys also matched 22 samples from infections in the wild to a separate command server. Two samples targeted BitKeep, adding a nineteenth wallet target.
Certificate records connected that infrastructure to Tencent hosting and lab systems in Shenyang, China. The researchers distinguished this operator from the exposed-directory cluster and did not name either group.
Development files referenced CVE-2026-31001, described as a JavaScriptCore type-confusion issue aimed at iOS 26. However, companion sandbox and kernel stages were placeholders.
This was unfinished work, not a deployed iOS 26 attack. A separate CoreAudio zero-click claim in the operator registry also remained unverified on a device.
Defenders should prioritize current iOS updates and track server fingerprints alongside network indicators.
Censys says the established chains are patched, while Apple confirms that DarkSword fixes were extended to more iOS 18 devices. Changing payload hashes mean hash-only detection will miss variants; shared code signatures offer wider coverage.
Indicators of compromise (IoCs):-
Network and Infrastructure Indicators
All entries below come from the source report. Association with an operator’s lab or management system does not establish that a host served malware. Infrastructure status reflects the report’s observations, not a fresh availability check.
| Type | Indicator | Role or context |
|---|---|---|
| IP:port | 43.134.165[.]205:9999 | DS-Fusion v1.0 distribution bundle |
| IP:port | 166.88.95[.]90:9999 | Operational command server with beacon telemetry |
| IP:port | 23.148.212[.]237:8888 | Operator analysis workspace; unfinished iOS 26 development |
| IP:port | 47.102.192[.]23:9876 | Coruna staging host |
| IP:ports | 156.239.230[.]120:8080, 156.239.230[.]120:80 | Exposed control platform and landing page |
| IP:port | 185.189.45[.]40:8080 | Earlier payload capture containing GHOST exploit stages |
| IP / domain | 112.213.108[.]85 / hdios[.]cn | Production server; hostname VM-NJb8T5qJl6 |
| IP / domain | 154.18.187[.]160 / fc.rsqqq[.]top | Backup delivery stack; hostname SG-B20702-I |
| IP / domain | 202.146.222[.]253 / i.131422[.]com | Former production server; hostname C202609121655717 |
| IP / domain | 203.91.77[.]253 / st.onlinefc[.]top | Operator work machine |
| IP:ports | 154.217.250[.]206:80, 154.217.250[.]206:888 | Suspected operator panel; moderate-confidence assessment |
| IP:port | 14.128.47[.]81:443 | Separate deployment of the group-named control panel |
| Domain | ccwu[.]cc | Parent domain of three panel-related subdomains; individual names not supplied |
| Domain | wumian[.]cc.cd | Panel-related hostname |
| C2 URL | hxxps://66ds[.]lol | Separate operator’s command server in 22 wild samples |
| Origin IP | 101.35.158[.]183 | Tencent-hosted origin behind the Cloudflare-fronted domain |
| Domain | iplcz[.]cn | Operator lab parent domain |
| Lab domains | northlab[.]cn, g.northlab[.]cn, manager.g.northlab[.]cn | Lab and management infrastructure; not identified as payload-serving hosts |
| Lab IPs | 218.25.85[.]177, 218.25.85[.]178, 59.46.4[.]117, 59.46.4[.]119 | Shenyang mail and lab infrastructure |
| Fallback C2 | hxxp://199.30.90[.]154:18090 | Hardcoded lab deployment host in the implant |
| Fallback pattern | hxxps://backup%u[.]fit | Wallet framework fallback replaced in wild builds |
| Operator contact | @v66db | Telegram sales contact on the landing page |
| Operator contact URL | hxxps://t.me/YATA0000 | Hidden contact link in the control panel |
| Historical campaign domains | siekeltd[.]com, escofiringbijou[.]com | Earlier DarkSword campaign indicators cited in the report’s references; not newly discovered cluster hosts |
Payload and Panel Hashes
These values are reproduced exactly from the report. Censys did not label the algorithm of the 40-character shared module hash, so it is not presented as a confirmed SHA-1 value.
| File or artifact | Hash type | Value |
|---|---|---|
bootstrap.dylib | SHA-256 | c391bce7b09a0ea263e4b2c1d1bde0327c180723fa3299b006485429564c61ee |
stage2.dylib | SHA-256 | 8973e80ab494c02463d4123f76fc5e2dca2ea2c097317d246323d75c1f2eb791 |
core_v6.dylib | SHA-256 | a50c4da5c92636b2b1f170cdce3bd967a213886a8df5656cf3519214fcecfac5 |
core_a5.dylib | SHA-256 | 54a4166ab33ffe02b41de9c943e783d20129b6cc22f56b7fe7d564fd02bde006 |
future-destroy.htm | SHA-256 | 7ff5bb16cd5f8c92bc4fec72bba162662f202af075418db5000a1b4f81489fc2 |
| Shared Coruna payload module | Algorithm unspecified | 1334417664270db20af705f422878c53c8378203 |
| Control-panel page body | Body hash, algorithm unspecified | 864d68e64618d6bfc26d75d6f780ae0b7bfed3698cc8333818ed32519e560d1f |
Device, File, and Certificate Artifacts
These artifacts can support investigation when found alongside other evidence; generic filenames or cookies alone should not be treated as proof of compromise.
| Artifact type | Value | Context |
|---|---|---|
| LaunchDaemon path | /Library/LaunchDaemons/com.apple.ds.agent.plist | Device-side persistence |
| LaunchDaemon label | com.apple.ds.agent | Persistence service label |
| Command channel | /tmp/nb_cmd | Local interprocess command channel |
| Result channel | /tmp/nb_result | Local interprocess result channel |
| Cookies | ds_uuid, ds_done, coruna-lab-session | Device/session tracking |
| Wallet modules | wallet01 through wallet18 | Eighteen wallet theft modules |
| BitKeep module | wallet19, libbitDylib.dylib, aware_retreat.css | BitKeep identifiers and disguised module filename |
| Delivery artifacts | group.html, exploit_server.py, darksword.db | Landing page, delivery service, and control database |
| Telemetry files | c2_results.jsonl, reports.jsonl | Command results and device reports |
| Development files | rce_worker_26.js, kernel_priv_26.js, vchain/ | Unfinished iOS 26 work; not evidence of a deployed chain |
| Older delivery chain | gooll/, gooll.html, entry1_type0x09.dylib | Chain targeting older iOS versions |
| Delivery and variant artifacts | /ios18/frame.html, manifest.json, daily_render.php, variants/set0 | Version routing and changing payload builds |
| Certificate issuer | Codex iOS Isolated Lab Root CA 2026 | Private certificate authority linking the separate operator’s origin |
| Certificate organization | IPLCZ Test Lab | Certificate pivot used to identify the origin |
| Panel identifiers | C2 Control Panel, C2 PANEL v3.0, 幽灵集团 | Panel title, version banner, and group name |
Embedded Keys and Configuration Strings
The following are malware configuration values published by Censys, not victim credentials.
| Configuration artifact | Exact value | Purpose |
|---|---|---|
| AES key | Ek8pl31K2yeHgQwy | Shared data-transfer encryption |
| Wallet deployment seed | UNDEFINED_DEPLOYMENT_SEED | Domain generation |
| Wallet reporting seed | UNDEFINED_REPORTING_SEED | Domain generation |
| 7z fallback password | c73dfcfd60a0c7ebcc03352d433349bc | Fallback transport configuration; not the build-time archive password |
| Plasma deployment seed | 09d0b8d58a71653cd1c89c64c866f2e6 | Deployment domain pool |
| Plasma reporting seed | 2d2aebba0bf3d7d694194a7ab93b0a96 | Reporting domain pool |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.