SlowMist: DarkSword attack program has been leaked online, and older iOS users' cryptocurrency wallets face serious risks
SlowMist reports that the high-risk iOS attack framework DarkSword has been leaked and used for large-scale thefts targeting cryptocurrency wallet holders. The attack targets iOS 18.4–18.7, exploiting Safari vulnerabilities via malicious web pages to achieve remote code execution, stealing plaintext private keys and mnemonics. The bait websites include fake porn live streams, TRON energy stations, refund processes, and more. Users on older iOS versions may have their information maliciously stolen by JavaScript when unlocking their wallets after visiting, with data transmitted back via Telegram bots.