Researchers say a newer variant of the DarkSword iOS exploit chain, called P7 DarkSword, continues to be used to attack cryptocurrency wallets through iOS vulnerabilities. The activity is linked to the Coruna malware payload, which is designed to steal cryptocurrency wallet information. Reports also describe the kit as using techniques to access parts of iOS involved in launching apps and interacting with the user interface.

Security researchers at Censys and iVerify report finding deployments of DarkSword/Coruna on attacker-controlled servers and identify multiple wallet applications as targets. The coverage says the malware’s purpose is wallet theft, including efforts to locate cryptocurrency recovery phrases. One outlet further reports that the newer variant reduces its on-device footprint and adds additional on-device theft features and a two-way command-and-control communication method.

Across the reporting, the main mitigation focus is patching. Previous DarkSword-related issues are described as fixed in newer iOS versions, while older, unpatched devices are flagged as more vulnerable. The outlets also note iOS versions that remain exposed and recommend keeping iPhones updated to current security releases.