Censys uncovered five exposed open directories revealing a DarkSword/Coruna iOS exploitation and cryptocurrency-theft platform, including exploit stages, delivery infrastructure, administrative tools, and wallet-harvesting modules. DarkSword provides device access through browser exploitation, while Coruna injects wallet-specific theft modules into cryptocurrency applications and searches photos and Apple Notes for valid recovery phrases. A separate production-server capture contained 11 victim recovery phrases, 179 device-loot directories, and a 75-account roster, supporting researchers’ assessment of a Chinese-speaking commercial exploitation-as-a-service operation with reseller-style administration. These findings do not establish the total number of victims or cryptocurrency losses.
Telemetry showed sustained beaconing from two devices in China and Hong Kong. Researchers also identified a separate China-based operator through 22 samples from infections in the wild configured to communicate with 66ds[.]lol; neither operator was named. Development artifacts referenced unfinished iOS 26 exploitation associated with CVE-2026-31001, but researchers found no evidence that this chain was operational or deployed. A separate CoreAudio zero-click capability claim also remains unverified. Established exploit chains are reportedly patched, making current iOS updates a priority for organizations supporting iPhones, particularly devices used to access cryptocurrency wallets.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
Censys published findings detailing wallet-module injection, recovery-phrase extraction from photos and Notes, and reseller administration capabilities. The report assessed the exposed cluster as a Chinese-speaking commercial exploitation operation distinct from previously documented DarkSword actors, without naming an operator.
The platform at 156.239.230[.]120 polled a device and remained operational during triage. It also served a Chinese-language watering-hole page displaying Telegram sales contact @v66db.
Telemetry recorded two devices running iOS 16.3.1 and iOS 16.1 polling every three seconds, producing 1,940 reports from Hangzhou and 2,749 from Hong Kong. Both sessions used zh-CN language headers and iPhone Safari user agents.
Between September 15 and September 17, Censys identified five previously undocumented hosts through its open-directory index. The exposed systems included a DS-Fusion distribution bundle, an operational command server, an analysis workspace, Coruna staging infrastructure, and a control platform.
Google Threat Intelligence Group first publicly documented the DarkSword/Coruna kit, which combines iOS exploitation with post-exploitation payloads.
Google Threat Intelligence Group observed multiple threat actors adopting the DarkSword/Coruna exploitation kit beginning in late 2025.
iVerify disclosed P7 DarkSword, a previously unseen variant that reduces on-device logging and processes stolen keychain data locally before exfiltration. Its SpringBoard implant supports bidirectional command-and-control, operating-system commands, arbitrary JavaScript execution, and extraction of cryptocurrency-wallet data, photos, and Notes.
Apple confirmed that DarkSword fixes had been extended to additional iOS 18 devices. Censys reported that the established 18.x exploit chains were patched in iOS 18.7.3 and iOS 26.3.
Development artifacts in an analysis workspace and production directory described CVE-2026-31001 as a JavaScriptCore type-confusion vulnerability, but companion sandbox and kernel stages were placeholders. Researchers found no evidence of deployed iOS 26 exploitation and could not verify a separate claimed CoreAudio zero-click capability.
Researchers identified 22 wild-build samples configured to communicate with 66ds[.]lol and distinguished their operator from the exposed-directory cluster. Certificate analysis linked the command infrastructure to origin 101.35.158[.]183 and Shenyang laboratory infrastructure, while two BitKeep modules expanded the observed wallet target set to 19.
Analysis of a separate production-server package revealed 11 victim recovery phrases, 179 device-loot directories, and 75 accounts with commissions and device quotas. The package's acquisition method was unknown, and the records did not establish the total victim count or cryptocurrency losses.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcecensys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.