Coruna and DarkSword iOS Exploit Kits Targeting Users Globally

Coruna and DarkSword iOS Exploit Kits Targeting Users Globally

First seen 10 Aug 2026, 22:47 UTC Darkreadingiverify.io 83% similarity 75.9

Article Content

Browse articles
ThreatCluster

The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation variants of these exploit chains. The exploits target iPhones running iOS versions 13 through 18.7, utilizing multiple vulnerabilities including CVE-2025-31277 and CVE-2026-20700. These exploit kits allow for remote code execution and privilege escalation, posing significant risks to ordinary users. Recent modifications by threat actors have enhanced their capabilities, making them easier to deploy. The situation reflects a concerning trend of sophisticated malware leaking from state use to broader criminal adoption. iVerify and Palo Alto Networks have noted hybrid variants combining techniques from both exploit kits. The ongoing analysis and tracking of these threats continue as infections persist months after initial disclosures.

Key Points: • Coruna and DarkSword exploit kits are now widely used by cybercriminals. • Approximately 17,000 domains linked to these exploit chains have been identified. • Threat actors are modifying the exploit frameworks, increasing their effectiveness.

ThreatCluster AI How this analysis works

Timeline

2025-07-29
CVE-2025-31277 published
A JavaScriptCore memory-corruption flaw was disclosed, affecting iOS devices.
Darkreading
2025-12-12
CVE-2025-43510 published
A memory management flaw in the iOS kernel was disclosed, impacting various iOS versions.
Darkreading
2025-12-12
CVE-2025-14174 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-12
CVE-2025-43520 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-15
CVE-2025-43529 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-02-11
CVE-2026-20700 published
A user-mode pointer authentication code bypass vulnerability was disclosed for iOS.
Darkreading
2026-03-20
CVE-2025-31277 added to CISA KEV
CISA listed the vulnerability as actively exploited, highlighting its significance.
Darkreading
Recent
Coruna and DarkSword infections persist
Infections from these exploit kits have continued for months after initial public disclosures.
iVerify.io

Community

Browse all →

Tracked Entities in This Story