Security
Eleven Seed Phrases on an Open Directory
Censys found five servers with open directories exposing a DarkSword/Coruna iPhone exploit platform, still in use, with an admin panel that pays resellers commission on infected devices. A copy of its production server held 11 victim recovery phrases, 179 device loot directories and 18 wallet-theft modules. iVerify's P7 variant polls its operator every 15 seconds and ships commands named wallet_scan and wallet_extract. Every bug it uses is patched; the exploit still works on phones that have not updated.
Between September 15 and 17, Censys's internal index of open directories turned up five hosts nobody had documented. Together they exposed what the firm's October 7 report calls "the full DarkSword/Coruna iOS exploit-and-harvest platform, from the C2 delivery server to the per-wallet theft modules." A copy of the production server, whose origin Censys says it could not establish, contained 11 victim recovery phrases, 12-word BIP39 seeds covering TronLink, Bitget, Bitpie, Trust, Phantom and imToken wallets, along with 179 device loot directories, a 75-account control-plane roster, and more than 87 on-chain addresses. "The infrastructure was still in use at triage time," the report says.
DarkSword is the iPhone exploit chain that Google's Threat Intelligence Group, iVerify and Lookout disclosed in March. It strings together six iOS vulnerabilities, three of them exploited as zero-days before Apple patched them, to go from a web page to kernel privileges on iPhones running iOS 18.4 through 18.7, per The Hacker News and Help Net Security. It has been in the wild since at least November 2025, and Google reported campaigns in Saudi Arabia, Turkey, Malaysia and Ukraine run by a suspected Russian state group and by customers of a Turkish surveillance vendor. Coruna is a companion chain for older phones, iOS 13 through 17.2.1. What the Censys and iVerify reports add, two weeks apart, is who else is using it now and what for.
Exploitation as a service
The platform Censys recovered is a business. Its admin panel has agents and resellers, each with a commission rate, a device quota the code calls max_devices, and their own channels. The report does not give the actual rates or quotas. The kit ships 18 wallet injection modules, one per app; the ones the report names are Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Uniswap and OKEx, and builds found in the wild add BitKeep as a nineteenth. Each module pulls what its app stores, keystores and balances included. The core implant also scans Photos and Notes for anything that looks like a recovery phrase and sends only the phrases that pass the BIP39 checksum, which filters out the false matches a screenshot of a word list would otherwise produce.
The telemetry was live. On September 6, two real iPhones, one in Hangzhou on iOS 16.3.1 and one in Hong Kong on iOS 16.1, polled a beacon page every three seconds for hours, 4,690 log lines between them. Censys attributes the cluster, with moderate confidence, to a Chinese-speaking operator distinct from six other DarkSword operators it tracks, with an origin server on Tencent in Shanghai and a lab domain resolving to Shenyang. It does not name anyone.
The five hosts
| Host | What it served |
|---|---|
| 43.134.165[.]205:9999 | "DS-Fusion v1.0," a packaged bundle of DarkSword and the Coruna payload tree |
| 166.88.95[.]90:9999 | Operational C2: implant kit, beacon backups dated September 3, live telemetry |
| 23.148.212[.]237:8888 | Operator workspace for iOS 26 exploit development; serves no payloads |
| 47.102.192[.]23:9876 | Coruna watering-hole staging, with per-victim payload directories |
| 156.239.230[.]120:8080 | The full C2 platform: delivery script, admin panel and database |
The report is explicit about what the numbers do not say. The production-server package describes itself as the output of an authorised red-team exercise; "We do not credit that description," the authors write, having found no evidence of any such engagement. The 179 loot directories are not 179 confirmed victims. An audit of the recovered addresses found about 0.3 TRX directly sweepable, with the caveat that value may sit in derivation paths the audit did not check. And the iOS 26 work on the third host, a JavaScriptCore type confusion the operator is developing as a seventh CVE, is unfinished: its kernel and sandbox-escape stages are placeholders and its build scripts flag self-test failures. "Not a zero day," Censys says, because it is not deployed. The iOS 18 bugs DarkSword relies on are fixed in iOS 18.7.3 and 26.3.
P7 asks every 15 seconds
iVerify's contribution is a single infected phone. In August, the firm got an alert for a DarkSword infection on a customer's device that looked slightly wrong, and with the customer's consent ran incident response on it; 9to5Mac reports the device belonged to an employee at a financial institution. The forensics showed a variant nobody had catalogued, which iVerify's October 8 report names P7 after the p7_ prefix its authors put on their variables. It is not a new vulnerability. It is a new implant, installed after the same exploit chain lands, and it is built for theft rather than surveillance.
P7 injects into SpringBoard, the iOS process that draws the home screen, and from there polls a /beacon endpoint every 15 seconds for tasking; the interval "is configurable from the C2 via the sleep command." Its handlers read like a menu: download, photos, apps, a file_upload, an exec that runs attacker JavaScript inside the implant, memo_scan for the Notes database, photo_scan, and two that give the variant its purpose. wallet_scan "Scans for installed wallet apps." wallet_extract "Extracts wallet-related data for imToken wallet app." The keychain handling changed too. "Previous DarkSword versions copied and exfiltrated the keychain database," the report says; P7 "extracts keychain data into JSON on the phone for exfiltration," leaving a keychain_c2_dump.json in /private/var/tmp on the way out. It strips its own debug logging, uses browser localStorage to avoid re-exploiting a phone it already owns, and talks to its operator over HTTPS "but without strict certificate validation." Its exploit components are labelled for iOS 18.4, 18.5, 18.6 and 18.7.
One sentence in the report deserves its own line, because it is the part that speaks to how this code is being written in 2026: "Unlike the many AI-assisted variants we observe, the P7 authors understood the code they were modifying." iVerify is saying two things at once. Most DarkSword forks it sees bear the marks of a language model, and this one does not.
A dead startup's tracking tag
How a phone reaches the exploit is the third report, from Report URI, as relayed by The Hacker News on October 11. The domain ecomtrack[.]io belonged to a Czech e-commerce analytics startup that no longer exists. Its registration lapsed, and on September 15, 2026, someone re-registered it. Online stores that never removed the startup's tracking tag now load whatever the new owner serves, which Report URI found to be JavaScript that hides from crawlers, fingerprints the visitor, and redirects a selected few through advertising networks to scam pages and casinos. One route ends at a fake crypto trading site, chainmate[.]top, that serves the DarkSword chain. The build Report URI recovered contacts a server at mertio[.]cc every 30 seconds and, in Scott Helme's words, "targets far more crypto wallets" than the earlier versions. iVerify separately says P7's operators distribute it through malicious advertising rather than by targeting individuals, per 9to5Mac. September 15 is also the first day of Censys's discovery window; the reports do not connect the two, and neither does this desk.
Apple's position is that all of this is patched. Censys says the iOS 18 bugs are closed in 18.7.3 and 26.3, and 9to5Mac notes that Apple has pushed 18.7.7, which broadened its DarkSword protections, to devices that can run iOS 26 but have not upgraded. Each report ends with the same instruction, which is the one the exploit depends on nobody following.
The Take
Eleven seed phrases is a small number, and Censys is right to say the loot directories are not a victim count. The finding is not the haul. It is the panel. Somebody built an iPhone exploit platform with reseller accounts, commission rates and per-agent device quotas, and left it on an open port while two phones in China checked in every three seconds. Crypto theft from mobile devices has a sales channel now, with the same structure as the hardware-wallet resellers and the fake-recruiter networks this desk has covered: a product, a margin, and a layer of agents between the operator and the person who gets hurt. The exploit itself is old. Every bug in it has a patch, and the patch has a date months in the past. What the platform sells is the gap between that date and the day a given phone updates, and the wallet_scan command exists because, inside that gap, the seed phrase in your camera roll is the most valuable file on the device.