SlowMist said an attack campaign disguised as a free VPS service is targeting iPhone Safari users on iOS 18.4 to 18.6.2. The malicious site event.polarnode.vip reportedly deploys a multi-stage exploit through a hidden iframe, reusing the DarkSword six-CVE chain including WebKit remote code execution, a GPU/mediaplaybackd sandbox escape, and kernel read/write access.
The campaign can recursively collect application files and Keychain data and capture keyboard input when imToken, TokenPocket, or TronLink is active in the foreground. SlowMist said a visit to the page alone does not confirm that mnemonic phrases or private keys were stolen, and that device forensics is needed to verify compromise. The firm advised users to upgrade to iOS/iPadOS 18.7.3 or 26.3+ and block wyincc.com, polarnode.vip, and port 36887.
SlowMist Warns Fake Free VPS Site Targets iOS Wallets With DarkSword Chain
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
