$ techbeacon▋
CVE & Exploits

Researchers Uncover DarkSword Platform Hijacking iPhones to Steal Crypto Wallets

Researchers Uncover DarkSword Platform Hijacking iPhones to Steal Crypto Wallets

Security researchers at Censys have identified a sophisticated exploitation framework, dubbed DarkSword (also known as Coruna), operating across five distinct servers. The infrastructure appears dedicated to infiltrating iPhone devices and exfiltrating the private keys that safeguard users' cryptocurrency wallets, highlighting a growing trend of mobile-focused financial theft.

The investigation began when analysts observed publicly exposed directories on the servers, which contained a suite of tools for delivering malicious payloads. Among the files were delivery scripts, implant binaries, and modules specifically designed to inject code into wallet applications, suggesting a turnkey solution for attackers to harvest crypto assets directly from compromised phones.

According to the findings, the platform leverages multiple stages of infection. Initial access is achieved through phishing links or malicious advertisements that prompt iPhone users to install a seemingly benign profile or app. Once installed, the implant gains elevated privileges, allowing it to monitor and intercept wallet transactions, retrieve seed phrases, and transmit the data back to the command-and-control servers.

What sets DarkSword apart from earlier iOS threats is its modular architecture, which enables operators to customize the payload for various wallet services. The researchers noted the presence of "wallet injection" components capable of targeting popular apps such as MetaMask, Trust Wallet, and Coinbase. By embedding itself within these applications, the malware can silently capture private keys without alerting the user.

The operation appears to be commercial in nature. Censys uncovered references to a reseller model within the server files, indicating that the tools are being offered to third‑party actors for a fee. This mirrors a broader underground market where sophisticated exploit kits are packaged and sold, lowering the barrier to entry for financially motivated cybercriminals.

Experts warn that the discovery underscores the urgency for users to adopt stronger security practices on their mobile devices. Regularly updating iOS, avoiding untrusted configuration profiles, and using hardware wallets for crypto storage can mitigate the risk. Meanwhile, security firms are expected to issue advisories and work with Apple to disrupt the identified infrastructure, though dismantling such a distributed platform may take time.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related