A dangerous hacking kit called DarkSword is still targeting older iPhone devices to steal cryptocurrency from popular crypto wallets. Cybersecurity experts from Censys have identified several servers hosting the malicious tools used to deploy the Coruna malware. This malware exploits vulnerabilities in Apple's WebKit and JavaScriptCore components, allowing hackers to access sensitive data from vulnerable iPhones.
Once inside a device, the Coruna malware focuses on crypto wallets, attempting to steal information that could give hackers access to users' funds. The affected wallet apps include Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken, and OKEx. The threat extends beyond wallet apps, as the malware can also scan through photos and notes on infected devices to locate BIP39 recovery phrases, which are crucial for recovering crypto wallets.
Apple has already patched the vulnerabilities exploited by DarkSword in iOS 26.3. However, older iPhone devices running iOS 26.2 and below, including older versions of iOS 18, may still be at risk if they have not been updated with the necessary security fixes. Crypto holders are advised to ensure their devices are up to date to minimize the risk of being targeted by these attacks.