Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft
A campaign targeting iPhones running iOS 18.4-18.6.2 via Safari is exploiting vulnerabilities consistent with the DarkSword lineage to steal files, Keychain data, and keyboard input, specifically targeting imToken, TokenPocket, and TronLink wallet applications. This campaign reuses previously disclosed vulnerabilities.
- Protocols
- imToken, TokenPocket, TronLink
- Confidence
- High
- First seen
- 4 Sep 2026, 10:30 UTC