malware
Published 2026-10-07
Verified 2026-10-09

Censys exposes DarkSword/Coruna iPhone exploit infrastructure: a commercial wallet-theft service with 18 crypto wallet modules that also scans Photos and Notes for recovery phrases; known chains are fixed in iOS 18.7.3 and 26.3

Censys published a report on 7 October 2026 after finding open directories, between 15 and 17 September, on five previously undocumented hosts used to deliver, stage and control the DarkSword iOS exploit chain and Coruna implants. DarkSword gets in through WebKit and JavaScriptCore browser exploits, escapes the Safari sandbox, gains kernel access and reaches SpringBoard, the process that runs the home screen and app launches. Coruna's core implant then watches for wallet apps to open and injects one of 18 matching modules, covering apps such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken and Bitpie. It also searches Photos and Apple Notes for BIP39 recovery phrases, sending only checksum-valid ones, and takes the address book. A copy of one production server held 11 victim recovery phrases, 179 device data folders and 75 operator accounts, and the admin panel supports agents, commissions and device quotas, which points to a theft service sold to others; Censys stresses this does not prove 179 victims. The 18.x chains are patched in iOS 18.7.3 and iOS 26.3. Censys also found unfinished development work on an iOS 26 chain built around a JavaScriptCore bug it tracks as CVE-2026-31001; it is not deployed, and Censys does not call it a zero-day. Censys published detection signatures for the Mach-O samples. Primary: Censys; wire: Cyber Security News.

Product
Apple iOS (WebKit, JavaScriptCore, kernel) on iPhone
Versions
iOS releases before 18.7.3 on the 18 line, and before 26.3 on the 26 line, for the known DarkSword chains
CVSS
Not stated for the chain; individual WebKit and kernel CVEs vary
Exploited in Australia?
unknown
Patch to
Update iPhones to the latest iOS (at least 18.7.3 or 26.3). Never keep wallet recovery phrases in Photos, screenshots or Notes; turn on Lockdown Mode for high-risk users, and move funds to a new wallet if a phrase was ever stored on the phone.

Primary: Censys — DarkSword/Coruna open directory finding report (7 Oct 2026) · Vendor: Apple security release notes (linked by Cyber Security News) · CVE: CVE-2026-31001 · Cyber Security News — DarkSword iOS exploit platform uses Coruna malware to steal wallet recovery phrases (8 Oct 2026)

vulnerabilities identity