Sophisticated iPhone exploit chains that were previously reserved for nation-state actors have suddenly and alarmingly spread to organized cybercrime groups around the globe. The complex malware frameworks, known as Coruna and DarkSword, are being used by a wide range of malicious actors, from advanced persistent threat (APT) groups to run-of-the-mill hackers.
According to research firm iVerify, at least 17,000 domains have been identified hosting second-generation versions of these exploit chains. This is a staggering number, especially considering that just a few months ago, these vulnerabilities were thought to be contained within nation-state and mercenary circles. The fact that they’re now being used by more conventional cybercriminals raises the stakes significantly.
So, what exactly are Coruna and DarkSword? These sophisticated exploit chains are designed to target iOS devices running various versions of Apple’s operating system. They utilize multiple vulnerabilities in software components such as JavaScriptCore, dyld, ANGLE, and the iOS kernel to achieve remote code execution (RCE), sandbox escape, and privilege escalation. The ultimate goal is to deliver malicious payloads that can be used for a variety of nefarious purposes.
DarkSword, in particular, has been linked to several high-profile campaigns targeting users in Malaysia, Saudi Arabia, Turkey, and Ukraine. It’s thought to have been developed by a government contractor and sold to zero-day brokers for mass iOS device targeting. Coruna, on the other hand, is an older framework that was initially discussed by iVerify last spring. It uses watering-hole attacks to compromise victims’ devices, injecting its code into legitimate system processes rather than running a dedicated spyware process.
The worrying trend here is that cybercriminals are not only adopting these exploit chains but also modifying and combining them in creative ways. Researchers at iVerify have observed threat actors using both Coruna and DarkSword against targets despite the two frameworks being distinct. In some cases, they’re even combining techniques from both platforms to create new, hybrid variants.
As Matthias Frielingsdorf, vice president of research at iVerify, notes, these exploit chains are “extremely easy to proliferate” and can be deployed in just a few minutes. This has significant implications for iOS users worldwide, as it means that even seemingly secure devices can be compromised with relative ease.
So what does this mean for you? The takeaway is clear: if you’re an iOS user, make sure your device is running the latest version of Apple’s operating system and keep all software up to date. Additionally, exercise caution when visiting unfamiliar websites or clicking on suspicious links, as watering-hole attacks can be used to compromise even the most secure devices. By being aware of these evolving cyber threats and taking simple precautions, you can significantly reduce your risk of falling victim to these sophisticated exploit chains.
Source: Dark Reading — 2026-08-10