Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecosystem for iOS exploit-kit abuse. The platform’s control plane and recovered victim artifacts show the operation was already collecting crypto-wallet recovery phrases and scaling access across multiple hosts. That structure increases the reach and monetization efficiency of DarkSword/Coruna activity.
Related Happenings
P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft
Malware Activity
H score16
First: 09.10.2026 19:29
Last: 09.10.2026 19:29
Sources 1
How related:
"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.
About this happening:
The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen...
P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft
Malware ActivityHow related: "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.
About this happening: The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor Meta
H score30
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
About this happening:
Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor MetaAbout this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
DarkSword iPhone exploit chain exploitation wave
Exploitation Wave
H score89
First: 18.03.2026 23:15
Last: 18.03.2026 23:15
Sources 1
How related:
An analysis of the production server's exploit registry has revealed that the DarkSword exploit kit comprises two CVE identifiers not previously documented -
About this happening:
DarkSword is an iPhone exploitation wave against Apple iOS devices that now includes a publicly leaked exploit kit used to run more than 100 web properties imp...
DarkSword iPhone exploit chain exploitation wave
Exploitation WaveHow related: An analysis of the production server's exploit registry has revealed that the DarkSword exploit kit comprises two CVE identifiers not previously documented -
About this happening: DarkSword is an iPhone exploitation wave against Apple iOS devices that now includes a publicly leaked exploit kit used to run more than 100 web properties imp...
Latest development: 09.10.2026 19:29
iVerify disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces its on-device footprint while adding on-device keychain and crypto-wallet theft plus two-way C2 communication. The implant is injected into SpringBoard, polls every 15 seconds, uses browser localStorage to prevent re-exploitation, and can collect iCloud Keychain data, Apple Notes, Photos, and wallet data. Censys also identified open directories on five hosts carrying DarkSword and Coruna components, and said the DarkSword exploit registry includes previously undocumented CVE-2025-24201 and CVE-2025-31200. The same ecosystem has also been tied to attacks against Saudi Arabia, Turkey, Malaysia, and Ukraine.
Timeline
-
09.10.2026 19:29 1 articles · 3h ago
DarkSword C2 records two Chinese iOS devices polling a beacon page
Detection Ioc UpdateThe 166.88.95[.]90 command-and-control server recorded two real Chinese iOS devices, 183.154.173[.]30 and 182.239.114[.]223, polling a beacon page every three seconds for several hours, indicating active use of the implant infrastructure.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
-
09.10.2026 19:29 1 articles · 3h ago
DarkSword platform polls a device through 156.239.230[.]120
Detection Ioc UpdateThe 156.239.230[.]120 node exposed the full DarkSword C2 platform and was observed polling a device on September 15, 2026, adding another live infrastructure signal tied to the DarkSword and Coruna ecosystem.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
-
09.10.2026 19:29 2 articles · 3h ago
Researchers tie DarkSword and Coruna infrastructure to a Chinese-speaking exploitation-as-a-service operation
Campaign Scope UpdateResearchers disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces on-device footprint while adding keychain and crypto-wallet theft plus two-way C2, and Censys linked the ecosystem to open directories on five hosts, a Chinese-speaking exploitation-as-a-service operation, and a separate China-based operator using 66ds[.]lol with BitKeep targeting. The production server also exposed victim recovery phrases, device loot directories, and a 75-account control-plane roster.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29