iverify.io
Coruna and DarkSword iOS Exploit Kits Targeting Users Globally
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation variants of these exploit chains. The exploits target iPhones running iOS versions 13 through 18.7, utilizing multiple vulnerabilities including CVE-2025-31277 and CVE-2026-20700. These exploit kits allow for remote code execution and privilege escalation, posing significant risks to ordinary users. Recent modifications by threat actors have enhanced their capabilities, making them easier to deploy. The situation reflects a concerning trend of sophisticated malware leaking from state use to broader criminal adoption. iVerify and Palo Alto Networks have noted hybrid variants combining techniques from both exploit kits. The ongoing analysis and tracking of these threats continue as infections persist months after initial disclosures.
Key Points: • Coruna and DarkSword exploit kits are now widely used by cybercriminals. • Approximately 17,000 domains linked to these exploit chains have been identified. • Threat actors are modifying the exploit frameworks, increasing their effectiveness.