The DarkSword platform is leveraging Coruna malware to illicitly obtain cryptocurrency wallet recovery phrases from iPhones. This operation transforms browser vulnerabilities into a practical service designed for theft.
Revealing the Mechanisms
Recently exposed server directories have provided insights into the platform’s mechanisms, revealing wallet modules, command systems, and records of stolen data. These findings offer a deeper understanding of the operation beyond its initial exploit chain.
Data from one server showed 11 victim recovery phrases, 179 directories of device data, and 75 operator accounts. While these figures suggest a commercial operation with agents and commissions, they do not confirm the total number of victims or the value of the stolen cryptocurrency.
Identification by Researchers
Researchers from Censys discovered the exposed DarkSword and Coruna infrastructure between September 15 and September 17, 2026. Their October 7 report linked five previously undocumented hosts to delivery, staging, analysis, and control systems. Some of the infrastructure was still active during the examination.
DarkSword provides the entry point into the device, while Coruna facilitates the theft of wallet information. The attack chain involves exploiting WebKit and JavaScriptCore to gain kernel access, subsequently reaching the iOS SpringBoard, which controls app launches and the screen.
Theft and Resale Platform
Upon accessing SpringBoard, the platform initiates three main components: a starting beacon, a second-stage controller, and a core implant. This system monitors wallet apps and injects theft modules into active apps, performing checks every three seconds.
The kit includes 18 wallet modules targeting popular apps like MetaMask, Phantom, and Trust Wallet. Researchers also noted that the implant searches photos and Apple Notes for recovery phrases, sending only those that pass checksum verification.
An exposed server revealed a Python delivery service and a FastAPI admin panel, supporting agent accounts and commission rates. Logs indicated consistent device activity, with iPhones checking a beacon page every three seconds on September 6.
Future Outlook and Recommendations
While evidence points to a sophisticated operation, Censys emphasizes the importance of keeping iOS devices up-to-date to mitigate these threats. Recent updates have patched known vulnerabilities, and Apple has expanded these fixes to additional iOS versions.
Defenders are advised to prioritize current updates, track server fingerprints, and utilize shared code signatures for better detection coverage. As the cyber landscape evolves, vigilance remains crucial to safeguarding digital assets.
