Leaked DarkSword iOS Exploit Chain 'P7' Now Steals Crypto Wallet Seeds and Keystores
The leaked DarkSword iOS exploit chain, originally attributed to state-level customers, has been repurposed by criminal actors to target cryptocurrency wallets. One visit to a malicious webpage on iOS 18.4–18.7 is enough for the implant to appear inside SpringBoard within seconds, decrypt the keychain on-device, locate seed phrases and keystore files, and send them to the attacker’s server.
DarkSword comprises six vulnerabilities, three of which were zero-days at the time of use: CVE-2025-31277 and CVE-2025-43529 in JavaScriptCore, CVE-2026-20700 in dyld, CVE-2025-14174 in ANGLE, and two XNU issues (CVE-2025-43510, CVE-2025-43520). Apple patched the flaws across iOS 18.7.2, 18.7.3, 26.1, 26.2 and 26.3.
Security firm iVerify first described the criminal P7 variant on 8 October. Researchers subsequently recovered a third build from a public sandbox archive dated 29 September 2026. The kit uses the lure domain iospc8[.]com, registered only six days earlier, and the previously unreported command server y21t8bcya6q9b7155a[.]cc.
Byte-for-byte comparison with the original GHOSTBLADE sample published by GTIG shows that P7 leaves the complex loader, TaskRop library and MIG-filter bypass untouched. Only the business-logic modules were rewritten: the new c2_agent.js drops Telegram, WhatsApp and iCloud collectors, adds direct Ethereum keystore decryption using PBKDF2/AES-CTR, and targets ten specific wallet bundle IDs including imToken, TokenPocket, Phantom and TronLink.
A second innovation, labelled “P7 Phase 2”, uses the AppleKeyStore service as an oracle. After copying keychain-2.db into /tmp, the implant opens an IOKit channel to securityd, unwraps class keys locally, and writes the decrypted JSON to disk before the agent exfiltrates it. This produces far smaller, immediately usable wallet packages than the original GHOSTBLADE behaviour.
Further passive reconnaissance revealed the “qqtime” delivery infrastructure active since at least July 2026. The same loader serves both the older Coruna chain for iOS 13–17.2.1 and DarkSword for iOS 18.x from a single iframe, confirming the hybrid “DarkCoruna” deployment pattern first noted by iVerify.
Related articles
Censys Exposes DarkSword iOS Exploit Platform and Coruna Crypto Wallet Stealer
Censys has disclosed the inner workings of DarkSword, a commercial platform that sells remote access to iOS devices, along with its associated malware Coruna that targets cryptocurrency wallet recovery keys. The infrastructure was exposed between September 15 and 17, allowing researchers to analyze the full attack chain starting from a WebKit and JavaScriptCore exploit delivered through the browser. After escaping the Safari sandbox and reaching the kernel, the platform deploys three layers including a flag, controller, and main implant. Coruna then scans the device for BIP39-compliant seed phrases stored in photos and Apple Notes across 19 targeted wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep. The exposed server contained 11 victim recovery keys, 179 directories of extracted data, and 75 operator accounts, indicating a structured commercial operation with agent accounts, commissions, and device quotas. Confirmed infections affect devices running iOS 16.1 and 16.3.1, while Apple has extended patches to additional iOS 18 devices. Maintaining updated iOS versions remains the primary defense against this threat.
How Malware Evades Sandboxes: Detection Techniques and Defense Strategies
Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.
Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers
Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.
Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware
Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.