Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise iPhones and harvest cryptocurrency wallet secrets.
Censys researchers uncovered delivery infrastructure, implants, wallet injection modules, and reseller controls.
At the same time, a separate production-server capture contained 11 victim recovery phrases, 179 device loot directories, and 75 control-plane accounts. The infrastructure remained active during September triage.
The five hosts surfaced between September 15 and 17, exposing a packaged DS-Fusion release, operational telemetry, an analysis workspace, Coruna staging files, and a complete command-and-control platform.
At 156.239.230[.]120:8080, researchers recovered exploit_server.py, a FastAPI administration application, and the darksword.db database.
The platform automatically registers devices, distributes exploit stages, queues commands, and organizes exfiltrated content.
Its agent model includes commission rates, device quotas, and separate delivery channels, while an integrated parser searches harvested files for BIP39 recovery phrases and cryptocurrency addresses.
These features expose the business machinery behind the attacks.
Censys investigation connects the exposed systems, through identical Coruna payloads, Chinese-language administration panels, and shared harvesting components.
Censys Researchers said that, the operation as commercial exploitation-as-a-service, although they cannot attribute the cluster to a named actor.
Telemetry from 166.88.95[.]90 showed two iPhones running iOS 16.1 and 16.3.1 polling a watering-hole beacon every three seconds for hours on September 6.
However, two initially suspicious exfiltration files on another host were only test-device reports, not stolen victim content.
After exploitation obtains kernel memory access, the recovered platform loads bootstrap.dylib, stage2.dylib, and the core_v6.dylib implant.
A SpringBoard coordinator disguised as future-destroy.htm watches wallet applications launch and injects matching theft modules into their running processes.
Eighteen modules target applications including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, and imToken.
The implant also searches photos and Notes for BIP39 mnemonics, transmitting only phrases that pass checksum validation.
Shared module infrastructure includes an embedded AES key, domain-generation fallbacks, separate exfiltration endpoints, and disabled TLS certificate validation.
The production capture provides evidence of theft, including 12-word recovery phrases associated with six wallet brands.
Nevertheless, its provenance remains unexplained, and the 179 loot directories should not be treated as a verified count of unique victims.
Researchers also identified 22 samples from infections using 66ds[.]lol, a separate Cloudflare-fronted C2. These builds preserve the shared wallet framework but substitute their own fallback address.
BitKeep modules expand the observed targeting to a nineteenth wallet application; certificate pivots connect this operator to Tencent and Shenyang infrastructure.
The exposed development files reference CVE-2026-31001, described by Censys as a JavaScriptCore type-confusion vulnerability targeting iOS 26.
However, companion sandbox-escape and kernel-privilege stages remain placeholders. The findings do not demonstrate a deployed iOS 26 exploit chain or active zero-day exploitation.
Google’s March analysis documented DarkSword’s six-vulnerability chain targeting iOS 18.4–18.7, distinct from older Coruna coverage.
Censys’s July panel-sprawl investigation demonstrated why stable panel fingerprints outperform rapidly changing domains for infrastructure tracking.
Google recommends updating to the latest iOS release and enabling Lockdown Mode when updates are unavailable.
Censys reports its detection coverage matched all 347 unique Mach-O binaries in the recovered sample set, supporting broader signature-based hunting beyond individual payload hashes.
| IP | Port | Hosting | First seen |
43.134.165[.]205 | 9999 | Tencent Cloud | 2026-09-15 |
166.88.95[.]90 | 9999 | Evoxt (Japan) | 2026-09-15 |
23.148.212[.]237 | 8888 | (unknown) | 2026-09-15 |
47.102.192[.]23 | 9876 | Alibaba Cloud | 2026-09-15 |
156.239.230[.]120 | 8080, 80 | (unknown) | 2026-09-16 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…