Known malicious kitcriticalstealer

DarkSword iOS exploit kit: fake captcha gate with a hidden exploit iframe (Coruna wallet stealer)

family: darksword-ios-exploit-2026-10

Delivery pages of the DarkSword iOS exploit chain, which installs the Coruna crypto-wallet stealer (recovery phrases and keystores from Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Bitget, BitKeep and others). The page poses as a 'Security verification' captcha, so far branded as OKX. A desktop visitor is told the site is not available on desktop and is shown a QR code to open it in Safari on a phone. A hidden x-safari-https:// link breaks out of the Facebook, Instagram and Line in-app browsers. A 0x0 iframe placed off-screen (/gooll/gooll.html) reads the iOS version (13 to 18, iPad included) and loads the exploit stages from a separate stage host. When it is done it asks the page to navigate to the genuine brand site, so the victim ends up on the real exchange.

Anchors

YARA ruleDarkSword_iOS_Exploit_Captcha_Gate
SMQL queryrun
contacted_host:hdios.cn OR contacted_host:ios.hdios.cn OR domain:*.131422.com OR contacted_host:i.131422.com OR contacted_host:ios.131422.com OR contacted_host:fc.131422.com OR contacted_host:rne8b0wt5znenjp.xyz OR contacted_host:cf.rne8b0wt5znenjp.xyz OR domain:*.hdykw.co OR contacted_host:ios.hdykw.co OR contacted_host:ipa.hdykw.co OR domain:*.tenso.cc OR contacted_host:ios.tenso.cc OR contacted_host:66ds.lol OR contacted_host:fc.rsqqq.top OR contacted_host:st.onlinefc.top OR domain:trxduih.top OR domain:*.trxduih.top

Provenance

Added: 2026-10-09 12:28
One hunt for the campaign. YARA anchor: the delivery page's structure (the postMessage redirect handler together with the hidden loader iframe or the captcha stylesheets and config, the Safari escape link with the gated overlay), or the loader document itself. It never keys on a brand, because each site's config names the brand it imitates. Search anchor: the delivery and stage hosts hdios[.]cn, ios.hdios[.]cn, i.131422[.]com, ios.131422[.]com, fc.131422[.]com, rne8b0wt5znenjp[.]xyz and cf.rne8b0wt5znenjp[.]xyz as exact hostnames, plus every subdomain of the operator domains 131422[.]com, tenso[.]cc and hdykw[.]co. On 2026-10-09 four more 131422[.]com subdomains (fdc, k, q and r1) served the kit page from the same server as ios.tenso[.]cc, and ios18.tenso[.]cc, an alias of htadmin.trxduih[.]top, showed a Chinese-language login to an "iOS operations centre", most likely the operator's panel (an assessment); ios.tenso[.]cc is an alias of i.131422[.]com. trxduih[.]top (registered 2026-09-05) is included on that link: its other hosts on the panel's server show a TRON "energy" and wallet-lookup page. Also included: the C2 of builds found in the wild, 66ds[.]lol, and the backup delivery hosts fc.rsqqq[.]top and st.onlinefc[.]top. hdykw[.]co is included on infrastructure overlap: ios.hdykw[.]co shared the delivery server with hdios[.]cn, and n.hdykw[.]co advertises a Windows remote-access tool that steals wallets, browser passwords and Telegram sessions. Read that link as an assessment, not proof. The exploit runs only on iOS, so a desktop capture shows the captcha gate, a QR code or an empty page, never the exploit. The loader's own comments are in Chinese and show active development, with iPad support added on 2026-09-11 and in-app browsers targeted from 2026-09-20.

Sightings (36)

HostScanScriptMatchWhen
hdios.cna7555e0f…https://hdios.cn/gooll/gooll.html#frame=0yara2026-10-09 19:07
hdios.cna7555e0f…—query2026-10-09 19:03
hdios.cna7555e0f…https://hdios.cn/#htmlyara2026-10-09 19:03
hdios.cna7555e0f…https://hdios.cn/gooll/gooll.htmlyara2026-10-09 19:03
t5.trxduih.top5c63ae78…—query2026-10-09 19:03
t4.trxduih.top3ebc3b49…—query2026-10-09 19:03
t3.trxduih.top5428ae9c…—query2026-10-09 19:03
t2.trxduih.topf23c5d57…—query2026-10-09 19:03
hdios.cna7555e0f…https://hdios.cn/yara2026-10-09 19:03
trxduih.top22f3fab4…—query2026-10-09 16:40
t1.trxduih.topd1f773e5…—query2026-10-09 16:40
htadmin.trxduih.topc69d5887…—query2026-10-09 16:40
ios18.tenso.ccc052140b…—query2026-10-09 16:33
r1.131422.com1f6347fe…—query2026-10-09 16:33
q.131422.com088773a1…—query2026-10-09 16:33
k.131422.com9fdfd622…—query2026-10-09 16:33
fdc.131422.com4938f143…—query2026-10-09 16:33
r1.131422.com1f6347fe…https://r1.131422.com/favicon.icoyara2026-10-09 16:24
q.131422.com088773a1…https://q.131422.com/favicon.icoyara2026-10-09 16:24
k.131422.com9fdfd622…https://k.131422.com/favicon.icoyara2026-10-09 16:24
fdc.131422.com4938f143…https://fdc.131422.com/favicon.icoyara2026-10-09 16:24
i.131422.comce4267b9…—query2026-10-09 16:05
i.131422.comce4267b9…https://i.131422.com/favicon.icoyara2026-10-09 16:04
hdios.cn520cf7c6…—query2026-10-09 15:12
hdios.cn520cf7c6…https://hdios.cn/#htmlyara2026-10-09 15:12
66ds.lol5a3ee8b9…—query2026-10-09 12:32
rne8b0wt5znenjp.xyz4f093cf2…—query2026-10-09 12:32
i.131422.com4db73eca…—query2026-10-09 12:32
ios26.tenso.ccf4a498b3…—query2026-10-09 12:32
n.hdykw.co50bdb61e…—query2026-10-09 12:32
hdios.cnfd741490…—query2026-10-09 12:32
hdios.cndad6a5dd…—query2026-10-09 12:32
rne8b0wt5znenjp.xyz2c0b8e24…—query2026-10-09 12:32
hdios.cnfd741490…https://hdios.cn/#htmlyara2026-10-09 12:32
hdios.cn#htmldad6a5dd…https://hdios.cn#htmlyara2026-10-09 12:32
rne8b0wt5znenjp.xyz#html2c0b8e24…https://rne8b0wt5znenjp.xyz#htmlyara2026-10-09 12:32