A high-risk iOS attack framework known as DarkSword has been publicly leaked on platforms like GitHub, according to ChainCatcher. This framework is being used in large-scale attacks targeting cryptocurrency wallet holders.
The attack specifically targets devices running iOS versions 18.4 to 18.7. It exploits vulnerabilities in the Safari browser through malicious websites to execute remote code and steal sensitive user data. Attackers use deceptive websites, such as fake adult live streams, Tron energy stations, and refund processes, to lure victims.
iPhone users with outdated iOS versions who visit these malicious sites using Safari may have their sensitive information, including plaintext private keys and mnemonic phrases, stolen by malicious JavaScript code. This data is then transmitted in real-time through channels like Telegram bots.