SlowMist|9月 04, 2026 11:01
🚨 Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft
SlowMist Security Team identified a campaign masquerading as a free VPS service. The landing page at event[.]polarnode[.]vip is a decoy that silently loads lk[.]js and screens for iPhone Safari on iOS 18.4–18.6.2.
Matching devices receive a hidden iframe (/dist/sandbox.html) that launches a multi-stage n-day chain reusing the DarkSword six-CVE chain: WebKit RCE, GPU / mediaplaybackd sandbox escapes, and kernel read/write.
Post-exploitation injects three plugins:
🔹 SpringBoard (sync.js) — recursively collects files from app containers, shared AppGroups, or absolute paths
🔹 securityd (auth.js) — collects genp / inet data from Keychain
🔹 kbd (input.js) — captures keyboard input when imToken, TokenPocket, or TronLink is in the foreground
MistEye reconstructed the delivery path and extracted C2, loader, and implant IOCs. When GTIG first observed DarkSword, three of the six CVEs were zero-days in the wild. By September 2026, all six had been publicly disclosed and patched by Apple, making the current delivery an n-day reuse of the DarkSword six-CVE chain.
❗️A page visit alone does not prove seed phrase or private key theft — confirm with device forensics first.
A free VPS page that only wants Safari on a narrow iOS range is not a VPS page. Update to iOS / iPadOS 18.7.3 or 26.3+, and block http://wyincc.com / http://polarnode.vip / port 36887.
Read the full analysis 👇
https://slowmist.medium.com/threat-intelligence-ios-safari-darksword-wallet-asset-theft-a7dc0e29cf95(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink