Researchers have uncovered a sophisticated exploit platform known as DarkSword, which uses Coruna malware to extract cryptocurrency wallet recovery phrases from iPhones. Discovered infrastructure included exposed server directories containing modules for wallet theft, command-and-control systems, and logs of stolen data — evidence of a full-fledged commercial theft operation. One production server alone showed 11 recovered wallet phrases, 75 operator accounts, and 179 “device loot directories,” though not all represented confirmed victims. Researchers identified the exposed infrastructure between September 15–17, 2026. Parts of the exploit framework and some servers were still active as of the report released on October 7.
DarkSword supplies the browser escape and kernel-level vulnerabilities that breach iOS defenses through WebKit and JavaScriptCore. Once the exploit chain achieves kernel access, it penetrates SpringBoard, the process managing apps and the system UI. Following those stages, three layers are loaded: a beacon for communication, a controller, and a core implant used for the theft.
The implant monitors for when supported wallet apps are launched (with a rate limit of one check every three seconds per app), then injects a theft module specific to that wallet. At least 18 wallet apps are targeted, including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep (the latter adding a nineteenth module). Beyond wallet apps, the implant also scans for recovery phrases stored in Apple Notes and the photo library. To reduce false positives, it keeps only phrases that pass validation checks (“checksum”). The implant also retrieves contacts, updates itself, and fetches daily settings. Data exfiltration is powered via multiple endpoints, using shared encryption keys, control settings, and infrastructure mimicking Safari behavior, including disabling TLS certificate verification.
In one server, operators used a FastAPI-based admin panel and Python service to manage the entire operation. This panel handled device registrations, command dispatch, exploit reports, agent accounts, commission schemes, and more than 60 possible commands. Logs showed two iPhones running iOS 16.1 and 16.3.1 repeatedly checking a beacon URL every three seconds over extended periods.
Among the exposed artifacts were launch daemons for persistence, local IPC channels (/tmp/nb_cmd, /tmp/nb_result), tracking cookies, payload modules, delivery scripts, and configuration files including an AES encryption key. Hashes for core payload files and certificates were documented. Notably, development files hinted at ongoing but unfinished work supporting iOS 26, including components for JavaScriptCore and kernel-based attacks; however, no fully deployed exploit chain for iOS 26 was verified.
The good news for defenders: the exploit chains used by DarkSword and Coruna have been patched. Apple confirmed that safeguards have been extended to more devices running iOS 18, though shifting payload hashes make hash-based detection unreliable. Broad code signature checks and keeping iOS fully updated are currently the most reliable defenses. Indicators of compromise published in the report include IP addresses, domains, file artifacts, module names, payload hashes, and certificate issuers.
Why This Matters
This threat blends chain exploits that break browser sandboxes with targeted modules for known wallet apps, making it especially dangerous. Crypto holders generally trust recovery phrases as their highest-value asset; once those are stolen, funds are irreversibly lost. The modular resale-style structure with commissions and device quotas suggests the operation is professional and scalable, likely serving many bad actors.
Looking ahead, both users and defenders should watch for evidence of newer, unpatched exploit chains—especially those targeting the latest iOS versions. For users, the takeaways are simple: update iOS promptly, avoid risky profiles or apps, and treat recovery phrase storage with extreme caution. For defenders and security teams, grouping detection using code signatures, network behavior, and server infrastructure will be more effective than depending on static hashes.