Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DarkSword Exploit Uses Coruna for Crypto Wallet Thefts

DarkSword Exploit Uses Coruna for Crypto Wallet Thefts

Posted on October 8, 2026 By CWS

The DarkSword platform is leveraging Coruna malware to illicitly obtain cryptocurrency wallet recovery phrases from iPhones. This operation transforms browser vulnerabilities into a practical service designed for theft.

Revealing the Mechanisms

Recently exposed server directories have provided insights into the platform’s mechanisms, revealing wallet modules, command systems, and records of stolen data. These findings offer a deeper understanding of the operation beyond its initial exploit chain.

Data from one server showed 11 victim recovery phrases, 179 directories of device data, and 75 operator accounts. While these figures suggest a commercial operation with agents and commissions, they do not confirm the total number of victims or the value of the stolen cryptocurrency.

Identification by Researchers

Researchers from Censys discovered the exposed DarkSword and Coruna infrastructure between September 15 and September 17, 2026. Their October 7 report linked five previously undocumented hosts to delivery, staging, analysis, and control systems. Some of the infrastructure was still active during the examination.

DarkSword provides the entry point into the device, while Coruna facilitates the theft of wallet information. The attack chain involves exploiting WebKit and JavaScriptCore to gain kernel access, subsequently reaching the iOS SpringBoard, which controls app launches and the screen.

Theft and Resale Platform

Upon accessing SpringBoard, the platform initiates three main components: a starting beacon, a second-stage controller, and a core implant. This system monitors wallet apps and injects theft modules into active apps, performing checks every three seconds.

The kit includes 18 wallet modules targeting popular apps like MetaMask, Phantom, and Trust Wallet. Researchers also noted that the implant searches photos and Apple Notes for recovery phrases, sending only those that pass checksum verification.

An exposed server revealed a Python delivery service and a FastAPI admin panel, supporting agent accounts and commission rates. Logs indicated consistent device activity, with iPhones checking a beacon page every three seconds on September 6.

Future Outlook and Recommendations

While evidence points to a sophisticated operation, Censys emphasizes the importance of keeping iOS devices up-to-date to mitigate these threats. Recent updates have patched known vulnerabilities, and Apple has expanded these fixes to additional iOS versions.

Defenders are advised to prioritize current updates, track server fingerprints, and utilize shared code signatures for better detection coverage. As the cyber landscape evolves, vigilance remains crucial to safeguarding digital assets.

Cyber Security News Tags:browser exploits, Censys research, Coruna malware, crypto wallets, cryptocurrency theft, Cybersecurity, DarkSword, Hacking, iOS exploit, JavaScriptCore, kernel access, mobile security, security flaws, wallet recovery phrases, WebKit vulnerability

Post navigation

Previous Post: Microsoft Teams Enhances Security Against Deepfake Threats

Related Posts

North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware Cyber Security News
MioLab Infostealer: Advanced Threat to macOS Users MioLab Infostealer: Advanced Threat to macOS Users Cyber Security News
Google AI Tool Uncovers 500+ XSS Vulnerabilities Google AI Tool Uncovers 500+ XSS Vulnerabilities Cyber Security News
New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware Cyber Security News
Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Cyber Security News
Microsoft Vulnerabilities 2026: Key Insights Revealed Microsoft Vulnerabilities 2026: Key Insights Revealed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • DarkSword Exploit Uses Coruna for Crypto Wallet Thefts
  • Microsoft Teams Enhances Security Against Deepfake Threats
  • Cybercriminals Target Crypto Users With Fake Firefox Extensions
  • Hikvision Camera Flaw Exploited in Cyber Attempts
  • Ransomware Affiliate Betrayal & Cybersecurity Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • DarkSword Exploit Uses Coruna for Crypto Wallet Thefts
  • Microsoft Teams Enhances Security Against Deepfake Threats
  • Cybercriminals Target Crypto Users With Fake Firefox Extensions
  • Hikvision Camera Flaw Exploited in Cyber Attempts
  • Ransomware Affiliate Betrayal & Cybersecurity Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark