iverify.io Coruna and DarkSword iOS Exploit Kits Targeting Users Globally
Article Content
- •Coruna and DarkSword exploit kits are now widely used by cybercriminals.
- •Approximately 17,000 domains linked to these exploit chains have been identified.
- •Threat actors are modifying the exploit frameworks, increasing their effectiveness.
The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation variants of these exploit chains. The exploits target iPhones running iOS versions 13 through 18.7, utilizing multiple vulnerabilities including CVE-2025-31277 and CVE-2026-20700. These exploit kits allow for remote code execution and privilege escalation, posing significant risks to ordinary users. Recent modifications by threat actors have enhanced their capabilities, making them easier to deploy. The situation reflects a concerning trend of sophisticated malware leaking from state use to broader criminal adoption. iVerify and Palo Alto Networks have noted hybrid variants combining techniques from both exploit kits. The ongoing analysis and tracking of these threats continue as infections persist months after initial disclosures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Kraken, Unc6353 and Coruna in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Malicious Chrome and Edge Extensions Target Crypto Users A coordinated malware campaign has compromised 19 browser extensions—18 for Chrome and 1 for Edge—designed to steal cryptocurrency wallet secrets and login credentials. The campaign, named 'Superior,' has been active since February 2024 and uses a strategy where legitimate extensions are acquired and later weaponized.…
MultiversX Network Exploit Triggers Trading Warnings from Upbit On September 21, 2026, Upbit issued a trading caution for EGLD following a mainnet security incident involving MultiversX. The incident was linked to an attempted exploit of a virtual-machine-level atomicity issue, which resulted in invalid state changes and forced the network to halt operations. As a precaution…