A new report by Censys security researchers warns that the DarkSword exploit in iOS continues to be used in conjunction with the Coruña malware to steal cryptocurrency wallets. Discovered earlier this year, DarkSword/Coruna is a double-edged hacking toolkit. DarkSword attacks WebKit and JavaScriptCore to access the iOS SpringBoard that manages app launch and splash screen. Coruña is the payload used to steal information from crypto wallets.
Censys’ investigation found several servers that had DarkSword/Coruna deployment directories. Targeted wallet apps include Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Uniswap, and OKEx. According to the site’s researchers, the main purpose of the exploit is wallet theft and also “extracts photos and notes for BIP39 recovery phrases.”