Newsroom
10 October, 2026 / News / AI / Tags: darksword, coruna, apps, ios, directories

Security researchers say the ongoing campaign using DarkSword and Coruna continues to threaten users of popular wallet apps on iPhones running older versions of iOS
Cybersecurity researchers have identified active deployment servers for the DarkSword exploit chain paired with the Coruna payload. The tools exploit vulnerabilities in WebKit and JavaScriptCore to gain code execution on iOS devices. Once inside, the malware injects into SpringBoard and harvests data from installed wallet applications. This activity persists months after initial public disclosure of the kit.
The campaign affects iOS 26.2 and earlier releases, including older versions of iOS 18 and prior. Apple released iOS 26.3 to close every known hole in the exploit chain. Devices still running those vulnerable versions remain exposed even after the patch went live.
The Coruna malware focuses on stealing sensitive information from cryptocurrency wallets. It scans browser sessions and installed apps to extract recovery phrases, account balances, and keystore data. The payload also searches through photos and Notes apps for BIP39 recovery phrases that could allow access to funds without needing the device itself.
Researchers documented the following wallet applications among those targeted: Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken, and OKEx. An additional China-based operator runs a variant of the same kit, hitting BitKeep and other apps through its own command-and-control servers.
DarkSword first compromises the browser sandbox, escalates privileges, and reaches the SpringBoard process responsible for app launching and the home screen. Coruna then deploys injection modules specific to each wallet. These modules extract data directly from running processes. One delivery path includes a self-adaptive kernel stage that fingerprints the device without explicitly naming its vulnerabilities.
Censys analysis showed five open directories exposing the complete platform. One served a packaged distribution bundle, another operated as a live telemetry server with active beacons, and others hosted staging pages, analysis workspaces, and full command-and-control interfaces. The operator runs a commercial exploitation-as-a-service model with reseller commissions and device quotas.
Production servers captured in the wild reported 11 extracted recovery phrases covering wallets such as Trust Wallet, Phantom, and imToken. Additional loot included on-chain addresses and directories containing device-specific data. A separate operator cluster, hosted in China, maintains its own identical kit infrastructure.
Apple addressed the vulnerabilities exploited by DarkSword through iOS 26.3. The update closed the WebKit and JavaScriptCore issues that enabled initial code execution. Older iOS versions lack these fixes and remain at risk.
Users should verify their device settings for the latest software release. Background Security Improvements can apply immediate patches without a full restart in some cases. Keeping apps and operating systems current remains the primary defense against browser-based exploits.
No widespread public breach data exists yet, but the continued presence of active servers and polling devices on known vulnerable hardware indicates the threat level stays elevated for anyone with an outdated iPhone.









