PT-2026-107674 · Undefined · Undefined
CVE-2026-31001
·
Published
2026-10-07
·
Updated
2026-10-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
#threatreport #HighCompleteness
DarkSword/Coruna Open Directory Finding Report | 07-10-2026
Source: https://t.co/CYqnWeWnOw
Key details below ↓
🧑💻Actors/Campaigns:
Unc6353
Unc6748
💀Threats:
Darksword tool, Coruna tool, Ds fusion, Gooll, Watering hole technique, Plasma, Ghost, Ghostblade, Ghostknife, Ghostsaber, Polymorphism technique, Spear-phishing technique,
🎯Victims: Cryptocurrency wallet users, Ios users, China
🏭Industry: Telco
🌐Geo: Cambodian, Japan, Asia-pacific, Hong kong, Chinese, China
🔓CVEs: CVE-2026-31001 [Vulners]
- CVSS V3.1: Unknown,
- Vulners: Exploitation: Unknown
CVE-2025-31200 [Vulners]
- CVSS V3.1: 9.8,
- Vulners: Exploitation: True Soft:
- apple macos (<15.4.1)
CVE-2025-24201 [Vulners]
- CVSS V3.1: 10.0,
- Vulners: Exploitation: True Soft:
- apple safari (<18.3.1)
- apple macos (<15.3.2)
- apple visionos (<2.3.2)
- apple watchos (<11.4) ...
📚TTPs:
⚔️Tactics: 1
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1005, T1027, T1036, T1041, T1055, T1059.004, T1059.007, T1068, T1071.001, T1082, ...
🧨IOCs:
- Hash: 6
- IP: 16
- Url: 3
- File: 12
- Domain: 11
💽Software: FastAPI, WhatsApp, Telegram, WeChat, contact tg, nginx, gement, m link, macOS, Cloudflare, ...
📲Wallets: bitkeep wallet, tronlink, imtoken, coinbase, metamask
🪙Crypto: uniswap
🔢Algorithms: aes
📜Programming Languages: php, javascript
💻Platforms: apple, arm
#threatreport:
The report documents a Chinese-speaking operator running the DarkSword iOS exploit chain and its companion Coruna wallet-theft platform through multiple exposed directories and control servers. The infrastructure was active during September 2026 and included exploit delivery, victim telemetry, payload staging, analysis environments, and an administrative C2 panel. The platform uses an agent/reseller model and reportedly contained 75 control-plane accounts, 179 device-loot directories, and 11 recovered victim recovery phrases.
DarkSword exploits WebKit and JavaScriptCore to achieve browser code execution, escape the sandbox, obtain kernel privileges, and inject into SpringBoard. Coruna then loads staged components, including a bootstrap beacon, plasma controller, and core implant. The implant monitors wallet applications and injects matching modules into running processes. Eighteen wallet modules target applications including Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Uniswap, and OKX. The malware also searches photos and Notes for checksum-valid BIP39 recovery phrases, collects wallet and keystore data, and can exfiltrate contacts and other device information. Shared capabilities include hardcoded AES encryption, domain-generation logic, multiple exfiltration endpoints, spoofed Safari user agents, and disabled TLS validation.
A separate delivery chain named gooll targets iOS 13.0 through 17.2.1. Its kernel stage fingerprints the device at runtime using XNU build data, driver patterns, and available IOKit services instead of relying on fixed offset tables. It uses multiple memory-access backends, bypasses Page Protection Layer defenses, and verifies kernel writes. The binaries do not identify the vulnerabilities used. The production registry also contains an unverified CVE-2025-31200 CoreAudio zero-click claim.
The operator is developing an iOS 26 chain centered on CVE-2026-31001, described as a JavaScriptCore type-confusion vulnerability. Its sandbox-escape and kernel stages remain placeholders, self-tests fail, and the chain has not been deployed; it should not be treated as a zero day or live capability.
Wild samples using a separate C2 at 66ds[.]lol include BitKeep modules, expanding the observed target set to 19 wallets. Infrastructure links connect this activity to Tencent-hosted systems in Shanghai and laboratory infrastructure in Shenyang. A 44-rule YARA set reportedly identifies the analyzed Mach-O payloads, exploit stages, coordinators, and wallet modules.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined