EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SlowMist警告:Darksword可能针对iOS 26.5钱包

2026-09-22 08:15:17
Bookmark

SlowMist警告:攻击者可能已调整Darksword漏洞链以入侵iOS 26.5设备并窃取私钥

核心摘要:

  • Darksword攻击通常始于iPhone用户在Safari浏览器中打开恶意链接。
  • SlowMist指出,攻击者可能已将漏洞链适配至iOS 26.5系统。
  • 谷歌此前确认Darksword活动针对的是iOS 18.4至iOS 18.7版本。
  • 三名美国投资者分别指控虚假钱包应用导致约183.5万美元的比特币损失。

攻击者利用Darksword绕过Apple安全控制

SlowMist首席信息安全官23pd表示,攻击者正在使用Darksword工具绕过Apple的安全控制措施,获取受影响iPhone设备的广泛访问权限,并收集本地安装的加密货币钱包中的数据。目前,关于iOS 26.5存在暴露风险的报告尚未得到Apple或Google的独立证实。Google威胁情报小组(GTIG)发布的研究报告记录了该工具对iOS 18.4至18.7版本的支持情况,而23pd声称攻击者随后修改了该工具以针对更新的操作系统。

Google威胁情报小组将Darksword识别为一个完整的iOS漏洞利用链,它结合了六个漏洞来 compromising 设备并交付不同的恶意负载。该公司追踪到相关活动至少从2025年12月持续到2026年3月。根据Google的说法,原始框架支持iOS 18.4至iOS 18.7。其中一个被用于iOS 18.6至18.7设备的缺陷(跟踪编号为CVE-2025-43529)影响了JavaScriptCore,即Safari中处理JavaScript的引擎。在Google报告此问题后,Apple已在iOS 18.7.3和iOS 26.2中修补了该漏洞。

尽管SlowMist的最新评估将潜在暴露范围扩展到了iOS 26.5,但该公司的声明尚未获得官方确认。警告中引用的技术分析并未明确说明是哪个漏洞或替代漏洞利用程序使Darksword能够攻破新版本系统。

恶意Safari链接可能泄露钱包数据

据23pd介绍,攻击者通常通过社会工程学手段发起入侵。目标用户通过社交网络、消息应用程序或其他通信渠道收到链接,并在Safari中打开该页面。随后,恶意网页内容试图利用浏览器和其他iOS组件,而无需用户安装常规应用程序。

一旦漏洞利用链成功,攻击者可能获得根级别的控制权。这种访问权限可以移除通常防止一个应用程序读取另一个应用程序文件和凭据的隔离机制,从而使存储在设备上的私钥和其他钱包记录面临风险。

Google发现多个组织使用Darksword配合不同的最终阶段恶意负载,而非单一的固定恶意软件。根据行动的不同,这些负载可能收集账户详情、消息、浏览记录、文件、位置历史、保存的Wi-Fi数据以及与加密货币钱包相关的信息。

安全公司将单独的行动与沙特阿拉伯、土耳其、马来西亚和乌克兰的受害者联系起来。Google将部分活动与商业监控提供商和疑似与国家有关的团体相关联,同时研究人员也发现有经济动机的行为者获得了高级iPhone漏洞利用工具的访问权限。SlowMist提供的材料中未包含通过Darksword被盗加密货币的具体受害者总数或确认金额。警告的重点在于该框架在攻破存储数据的设备后获取钱包信息的能力。

类似的交付方式曾出现在其他移动威胁中

一种类似的交付方式出现在早期的移动威胁中。今年三月,crypto.news报道了Google关于Coruna的发现,这是一个包含五个攻击链中23个漏洞的漏洞利用套件。Coruna针对运行iOS 13至iOS 17.2.1版本的iPhone,可以搜索“备份短语”和“银行账户”等术语的文件和图片。

Google研究人员表示,Coruna会在选择适合iPhone型号和软件版本的漏洞利用之前,先对访问者的设备进行指纹识别。一些操作者将该套件放置在虚假的赌博和加密货币网站上,当目标加载页面时,入侵便开始。

近期的iOS威胁主要针对私钥

Darksword并非近期涉及Apple设备上加密货币数据的唯一安全威胁。Binance于9月19日警告iPhone和iPad用户注意FomoPeek 1.1和1.2版本中发现的恶意代码。

研究人员在检查该应用时发现了一个包含八种攻击方法的内核漏洞利用框架,并宣布其支持覆盖iOS 12.0至18.7.2以及iOS 26.0至26.1版本。根据关于FomoPeek的报告,恶意模块可以逃离iOS沙盒,解密Keychain数据,并访问私钥、钱包恢复短语、账户凭据以及其他应用程序持有的文件。

Binance建议任何安装了受影响版本的用户卸载该应用,更新iOS系统,并避免重新安装它。自托管用户还被告知在干净的设备上创建新钱包并转移资产,因为如果私钥或恢复短语已被复制,删除恶意应用并不能保护钱包。

Darksword uses a different path because its recorded actions rely on malicious or tampered websites. However, both scenarios involve trying to defeat controls that typically prevent software from obtaining sensitive records from other locations on the iPhone. SlowMist recommends that users install mobile operating system updates in a timely manner and avoid opening unsolicited links sent by strangers. Google and Apple also view current software as a core defense because Apple has patched six vulnerabilities recorded in the original Darksword chain.

U.S. investors sue Apple over fake wallets

For U.S. crypto holders, Darksword's warning follows a controversy over the distribution of malicious wallet software through Apple's official market. According to previous court reports, three investors have filed a federal lawsuit alleging that a fake app appeared on the App Store posing as Sparrow Wallet, resulting in approximately $1.835 million in Bitcoin losses.

The plaintiff's allegations involve fraudulent applications, not browser-based exploits. Still, their case focuses on the security of Apple's mobile distribution systems and the financial damage that occurs when users trust seemingly legitimate cryptocurrency software.

Another fake app that impersonates Ledger Live allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT tracked funds from Bitcoin, Ethereum, Solana, Tron and XRP users to more than 150 KuCoin deposit addresses and a mixed-currency service.

The fake Ledger app requires users to enter their 24-word recovery phrases during a seemingly standard wallet setup process. Apple subsequently removed the list, and one victim said he downloaded it when configuring his Ledger device on his new MacBook.

Unlike Darksword chains, fraudulent Ledger applications do not require security controls that undermine the operating system. Users exposed their wallets by entering recovery phrases in counterfeit software, giving their operators control of all addresses derived from those phrases.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP