Gbhackers DarkSword Exploit Platform Targets iPhones to Steal Crypto Wallets
Article Content
- •DarkSword uses Coruna malware to exploit iPhones and steal crypto wallet secrets.
- •Exposed servers revealed 11 victim recovery phrases and 179 loot directories.
- •The operation is characterized as a commercial exploitation-as-a-service.
Exposed DarkSword servers have revealed a sophisticated platform using Coruna malware to compromise iPhones and steal cryptocurrency wallet recovery phrases. Censys researchers found operational telemetry, wallet injection modules, and records of stolen data, including 11 victim recovery phrases and 179 device loot directories. The platform employs a command-and-control infrastructure that registers devices and queues commands for exfiltration. Was observed, with telemetry showing infected iPhones polling a beacon every three seconds. The malware targets popular wallet applications such as MetaMask and Coinbase, injecting theft modules into their processes. While the exact number of unique victims remains unclear, evidence of theft has been documented. The operation appears to function as a commercial exploitation service, though no specific threat actor has been identified.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Coruna and CVE-2026-31001 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which iOS versions are affected?
How many recovery phrases were stolen?
What should users do to protect their wallets?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…