Back Darkreading Coruna, DarkSword iOS Exploits Proliferate Globally
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
The advanced iPhone exploit chains Coruna and DarkSword continue to escape nation-state and mercenary containment to enter the hands of more conventional cybercriminals.
While nation-state-grade malware will, from time to time, make its way from government use to cybercriminal adoption, it's far more unusual to see whole complex exploit chains — especially those targeting iOS — adopted broadly. Yet that phenomenon, first observed last spring , appears to be shifting into overdrive. iVerify has tracked approximately 17,000 domains hosting second-generation iterations of Coruna and DarkSword so far, and infections have continued months after public disclosure earlier this year.
"In five minutes, you can deploy an iOS exploit chain. ... This is extremely dangerous and extremely easy to proliferate," says Matthias Frielingsdorf, vice president of research at iVerify.
And cybercriminals are making improvements: After iVerify disclosed Coruna, threat actors apparently modified the framework, Frielingsdorf says; iVerify researchers saw new variants with improved jailbreak and virtualization detection functionality, improved encryption, Telegram-focused implants, new persistence mechanisms, and more.
Just as interesting, perhaps even more so, iVerify and Palo Alto Networks separately observed threat actors using both chains against targets despite DarkSword and Coruna being very much distinct. In a post, researchers at iVerify said telemetry and third-party reporting suggest some threat actors have adopted both frameworks, and in some cases appear to be combining techniques from the two platforms. iVerify informally named these hybrid variants "Darkuna," and noted they illustrate how operators continue to modify frameworks long after development and disclosure.
"These threat actors are actually changing quite a lot [with] this version," the researcher explains, adding that these newer variants incorporate updated process-injection targets, stronger anti-analysis functionality, and new implants in the modified framework.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7. It was used in campaigns linked to multiple commercial surveillance vendors and suspected state- actors to target users across Malaysia, Saudi Arabia, Turkey, and Ukraine. It's very sophisticated, utilizing multiple vulnerabilities: JavaScriptCore memory-corruption flaws CVE-2025-31277 and CVE-2025-43529; dyld user-mode pointer authentication code bypass CVE-2026-20700; ANGLE memory corruption flaw CVE-2025-14174; iOS kernel memory management flaw CVE-2025-43510; and iOS kernel memory corruption bug CVE-2025-43520 — all along with multiple malware families. Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery. Apple patched DarkSword in April .
Coruna, meanwhile, is a more mature exploit chain that targets iOS 13 through 17.2.1. Though iVerify first discussed the kit shortly before DarkSword, its toolset is thought to be years older, developed by a government contractor and sold to zero-day brokers for mass iOS device targeting. Coruna deploys 23 vulnerabilities across five exploit chains , and was thought to have cost between $30 million and $40 million to develop. Apple patched the older vulnerabilities behind Coruna in 2023 and 2024.
The framework uses watering-hole attacks, where victims visited compromised websites that deliver browser exploits, sandbox escapes, and privilege-escalation vulnerabilities. Once compromised, according to Frielingsdorf, Coruna injected its code into legitimate system processes such as the power daemon and location daemon rather than running a dedicated spyware process, making detection more difficult. It includes capabilities such as command and control (C2), application launching, process injection, data exfiltration, and cryptocurrency theft.
Frielingsdorf hosted a session at Black Hat USA 2026 last week diving deep into both DarkSword and Coruna, offering an analysis into the recent history of both exploit kits, and emphasizing that both represent the first time he's seen nation-state-grade iOS exploitation spill over into organized cybercrime at a meaningful level. For example, he connected Coruna infrastructure use to a Chinese organized crime group, and tied DarkSword deployments to multiple operators across the world (portions of the DarkSword exploit chain later appeared on GitHub). In other words, these don't belong to a single government or spyware operator.
"There is a strong difference between the operator of malware and who is actually authoring it in the first place and selling it," Frielingsdorf explains.
He also says DarkSword is designed to steal "basically everything," including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more. But particularly notable is the fact that DarkSword's data theft capabilities also targeted cryptocurrency wallets, indicating possible intended use by financially motivated cybercriminals from the get-go.
"These technologies are massively proliferating and trying to target as many devices as they can," Frielingsdorf warns, adding, "We're probably going to see more and more mass exploitation."
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
0-Day to 10x Discovery: Security at the Speed of Mythos
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
