Find notable cyber news and cases, enriched with sources, timelines, and signals.

Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model

Threat Actor Meta
First reported
Last updated
Happening score
H score 15
1 unique sources, 1 articles

Summary

Hide ▲

Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecosystem for iOS exploit-kit abuse. The platform’s control plane and recovered victim artifacts show the operation was already collecting crypto-wallet recovery phrases and scaling access across multiple hosts. That structure increases the reach and monetization efficiency of DarkSword/Coruna activity.

Related Happenings

P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft

Malware Activity
H score16 First: 09.10.2026 19:29 Last: 09.10.2026 19:29 Sources 1

How related: "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.

About this happening: The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen...

Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization

Threat Actor Meta
H score30 First: 01.09.2026 20:19 Last: 01.09.2026 20:19 Sources 1

About this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...

DarkSword iPhone exploit chain exploitation wave

Exploitation Wave
H score89 First: 18.03.2026 23:15 Last: 18.03.2026 23:15 Sources 1

How related: An analysis of the production server's exploit registry has revealed that the DarkSword exploit kit comprises two CVE identifiers not previously documented -

About this happening: DarkSword is an iPhone exploitation wave against Apple iOS devices that now includes a publicly leaked exploit kit used to run more than 100 web properties imp...

Latest development: 09.10.2026 19:29

iVerify disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces its on-device footprint while adding on-device keychain and crypto-wallet theft plus two-way C2 communication. The implant is injected into SpringBoard, polls every 15 seconds, uses browser localStorage to prevent re-exploitation, and can collect iCloud Keychain data, Apple Notes, Photos, and wallet data. Censys also identified open directories on five hosts carrying DarkSword and Coruna components, and said the DarkSword exploit registry includes previously undocumented CVE-2025-24201 and CVE-2025-31200. The same ecosystem has also been tied to attacks against Saudi Arabia, Turkey, Malaysia, and Ukraine.

Timeline

  1. 09.10.2026 19:29 1 articles · 3h ago

    DarkSword C2 records two Chinese iOS devices polling a beacon page

    Detection Ioc Update

    The 166.88.95[.]90 command-and-control server recorded two real Chinese iOS devices, 183.154.173[.]30 and 182.239.114[.]223, polling a beacon page every three seconds for several hours, indicating active use of the implant infrastructure.

    Show sources
  2. 09.10.2026 19:29 1 articles · 3h ago

    DarkSword platform polls a device through 156.239.230[.]120

    Detection Ioc Update

    The 156.239.230[.]120 node exposed the full DarkSword C2 platform and was observed polling a device on September 15, 2026, adding another live infrastructure signal tied to the DarkSword and Coruna ecosystem.

    Show sources
  3. 09.10.2026 19:29 2 articles · 3h ago

    Researchers tie DarkSword and Coruna infrastructure to a Chinese-speaking exploitation-as-a-service operation

    Campaign Scope Update

    Researchers disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces on-device footprint while adding keychain and crypto-wallet theft plus two-way C2, and Censys linked the ecosystem to open directories on five hosts, a Chinese-speaking exploitation-as-a-service operation, and a separate China-based operator using 66ds[.]lol with BitKeep targeting. The production server also exposed victim recovery phrases, device loot directories, and a 75-account control-plane roster.

    Show sources