DarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


DarkSword operators are using Coruna malware to steal cryptocurrency wallet recovery phrases from iPhones, turning browser exploits into a ready-to-use theft service.

Exposed server directories revealed wallet modules, command systems, and records of stolen data, giving researchers a closer look at how the platform works beyond its initial exploit chain.

A copy of one production server contained 11 victim recovery phrases, 179 device loot directories, and a roster of 75 operator accounts.

Those records point to a commercial operation with agents, commissions, and device limits. They do not establish 179 confirmed victims or show the total value of stolen cryptocurrency.

Researchers from Censys identified the exposed DarkSword/Coruna infrastructure through an internal index of open directories between September 15 and September 17, 2026.

In its October 7 report, the company linked five previously undocumented hosts to delivery, staging, analysis, and control systems. Some infrastructure remained active when researchers examined it.

DarkSword iOS Exploit Platform Uses Coruna Malware

DarkSword supplies the route into the device, while Coruna supplies the wallet theft tools. Earlier DarkSword exploit coverage explains how the chain attacks WebKit and JavaScriptCore, breaks out of the browser sandbox, and gains kernel access.

It then reaches SpringBoard, the iOS process that controls app launches and the screen. After that access is gained, the platform loads three main layers: a starting beacon, a second-stage controller, and a core implant.

The SpringBoard coordinator watches for supported wallet apps to open, then injects the matching theft module into the running app. Its injection checks are limited to one per three seconds for each app bundle.

The exposed kit contains 18 wallet modules targeting apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie.

DarkSword exploit chain (Source - Censys)
DarkSword exploit chain (Source – Censys)

Previous Coruna exploit analysis describes the wider toolkit behind this theft model. The newly examined implant also searches photos and Apple Notes for BIP39 recovery phrases, sending only phrases that pass checksum checks.

That checking step helps filter out random text before stolen material reaches the server. The implant can also collect contacts, update itself, and fetch daily settings.

Its wallet modules share an AES encryption key, backup domain-generation settings, and five data collection endpoints. They imitate Safari traffic and disable TLS certificate checks.

A Reseller Platform With Active Devices

One exposed server contained a Python delivery service and a FastAPI admin panel backed by a database. The service registers devices on their first visit, serves landing pages, collects exploit reports, and passes commands to implants.

The panel supports agent accounts, commission rates, device quotas, and more than 60 allowed commands. Separate logs showed two iPhones checking a beacon page every three seconds for hours on September 6. They ran iOS 16.1 and 16.3.1.

Earlier DarkSword infrastructure tracking documented rapidly changing servers and web properties; the latest findings expose the software and account structure behind that activity rather than just its public pages.

The evidence needs careful reading. Files first suspected of holding stolen browser data on one host proved to be small test-device reports.

The production-server copy provided stronger evidence of wallet recovery-phrase theft, but Censys said its origin was unknown. Researchers rejected its claim that it came from an authorized red-team exercise.

Censys also matched 22 samples from infections in the wild to a separate command server. Two samples targeted BitKeep, adding a nineteenth wallet target.

Certificate records connected that infrastructure to Tencent hosting and lab systems in Shenyang, China. The researchers distinguished this operator from the exposed-directory cluster and did not name either group.

Development files referenced CVE-2026-31001, described as a JavaScriptCore type-confusion issue aimed at iOS 26. However, companion sandbox and kernel stages were placeholders.

This was unfinished work, not a deployed iOS 26 attack. A separate CoreAudio zero-click claim in the operator registry also remained unverified on a device.

Defenders should prioritize current iOS updates and track server fingerprints alongside network indicators.

Censys says the established chains are patched, while Apple confirms that DarkSword fixes were extended to more iOS 18 devices. Changing payload hashes mean hash-only detection will miss variants; shared code signatures offer wider coverage.

Indicators of compromise (IoCs):-

Network and Infrastructure Indicators

All entries below come from the source report. Association with an operator’s lab or management system does not establish that a host served malware. Infrastructure status reflects the report’s observations, not a fresh availability check.

Type Indicator Role or context
IP:port 43.134.165[.]205:9999 DS-Fusion v1.0 distribution bundle
IP:port 166.88.95[.]90:9999 Operational command server with beacon telemetry
IP:port 23.148.212[.]237:8888 Operator analysis workspace; unfinished iOS 26 development
IP:port 47.102.192[.]23:9876 Coruna staging host
IP:ports 156.239.230[.]120:8080, 156.239.230[.]120:80 Exposed control platform and landing page
IP:port 185.189.45[.]40:8080 Earlier payload capture containing GHOST exploit stages
IP / domain 112.213.108[.]85 / hdios[.]cn Production server; hostname VM-NJb8T5qJl6
IP / domain 154.18.187[.]160 / fc.rsqqq[.]top Backup delivery stack; hostname SG-B20702-I
IP / domain 202.146.222[.]253 / i.131422[.]com Former production server; hostname C202609121655717
IP / domain 203.91.77[.]253 / st.onlinefc[.]top Operator work machine
IP:ports 154.217.250[.]206:80, 154.217.250[.]206:888 Suspected operator panel; moderate-confidence assessment
IP:port 14.128.47[.]81:443 Separate deployment of the group-named control panel
Domain ccwu[.]cc Parent domain of three panel-related subdomains; individual names not supplied
Domain wumian[.]cc.cd Panel-related hostname
C2 URL hxxps://66ds[.]lol Separate operator’s command server in 22 wild samples
Origin IP 101.35.158[.]183 Tencent-hosted origin behind the Cloudflare-fronted domain
Domain iplcz[.]cn Operator lab parent domain
Lab domains northlab[.]cn, g.northlab[.]cn, manager.g.northlab[.]cn Lab and management infrastructure; not identified as payload-serving hosts
Lab IPs 218.25.85[.]177, 218.25.85[.]178, 59.46.4[.]117, 59.46.4[.]119 Shenyang mail and lab infrastructure
Fallback C2 hxxp://199.30.90[.]154:18090 Hardcoded lab deployment host in the implant
Fallback pattern hxxps://backup%u[.]fit Wallet framework fallback replaced in wild builds
Operator contact @v66db Telegram sales contact on the landing page
Operator contact URL hxxps://t.me/YATA0000 Hidden contact link in the control panel
Historical campaign domains siekeltd[.]com, escofiringbijou[.]com Earlier DarkSword campaign indicators cited in the report’s references; not newly discovered cluster hosts

Payload and Panel Hashes

These values are reproduced exactly from the report. Censys did not label the algorithm of the 40-character shared module hash, so it is not presented as a confirmed SHA-1 value.

File or artifact Hash type Value
bootstrap.dylib SHA-256 c391bce7b09a0ea263e4b2c1d1bde0327c180723fa3299b006485429564c61ee
stage2.dylib SHA-256 8973e80ab494c02463d4123f76fc5e2dca2ea2c097317d246323d75c1f2eb791
core_v6.dylib SHA-256 a50c4da5c92636b2b1f170cdce3bd967a213886a8df5656cf3519214fcecfac5
core_a5.dylib SHA-256 54a4166ab33ffe02b41de9c943e783d20129b6cc22f56b7fe7d564fd02bde006
future-destroy.htm SHA-256 7ff5bb16cd5f8c92bc4fec72bba162662f202af075418db5000a1b4f81489fc2
Shared Coruna payload module Algorithm unspecified 1334417664270db20af705f422878c53c8378203
Control-panel page body Body hash, algorithm unspecified 864d68e64618d6bfc26d75d6f780ae0b7bfed3698cc8333818ed32519e560d1f

Device, File, and Certificate Artifacts

These artifacts can support investigation when found alongside other evidence; generic filenames or cookies alone should not be treated as proof of compromise.

Artifact type Value Context
LaunchDaemon path /Library/LaunchDaemons/com.apple.ds.agent.plist Device-side persistence
LaunchDaemon label com.apple.ds.agent Persistence service label
Command channel /tmp/nb_cmd Local interprocess command channel
Result channel /tmp/nb_result Local interprocess result channel
Cookies ds_uuid, ds_done, coruna-lab-session Device/session tracking
Wallet modules wallet01 through wallet18 Eighteen wallet theft modules
BitKeep module wallet19, libbitDylib.dylib, aware_retreat.css BitKeep identifiers and disguised module filename
Delivery artifacts group.html, exploit_server.py, darksword.db Landing page, delivery service, and control database
Telemetry files c2_results.jsonl, reports.jsonl Command results and device reports
Development files rce_worker_26.js, kernel_priv_26.js, vchain/ Unfinished iOS 26 work; not evidence of a deployed chain
Older delivery chain gooll/, gooll.html, entry1_type0x09.dylib Chain targeting older iOS versions
Delivery and variant artifacts /ios18/frame.html, manifest.json, daily_render.php, variants/set0 Version routing and changing payload builds
Certificate issuer Codex iOS Isolated Lab Root CA 2026 Private certificate authority linking the separate operator’s origin
Certificate organization IPLCZ Test Lab Certificate pivot used to identify the origin
Panel identifiers C2 Control Panel, C2 PANEL v3.0, 幽灵集团 Panel title, version banner, and group name

Embedded Keys and Configuration Strings

The following are malware configuration values published by Censys, not victim credentials.

Configuration artifact Exact value Purpose
AES key Ek8pl31K2yeHgQwy Shared data-transfer encryption
Wallet deployment seed UNDEFINED_DEPLOYMENT_SEED Domain generation
Wallet reporting seed UNDEFINED_REPORTING_SEED Domain generation
7z fallback password c73dfcfd60a0c7ebcc03352d433349bc Fallback transport configuration; not the build-time archive password
Plasma deployment seed 09d0b8d58a71653cd1c89c64c866f2e6 Deployment domain pool
Plasma reporting seed 2d2aebba0bf3d7d694194a7ab93b0a96 Reporting domain pool

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post DarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases appeared first on Cyber Security News.