Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains once limited to nation-states are spreading rapidly to organized cybercrime groups, posing a significant threat to global security.

Two advanced iOS exploit chains, Coruna and DarkSword, have been making headlines in recent months due to their complex nature and widespread adoption. Initially used by nation-state actors and commercial surveillance vendors, these exploit chains have now fallen into the hands of conventional cybercriminals, who are modifying and improving them for their own nefarious purposes.

According to researchers at iVerify, a cybersecurity firm that tracks the spread of malware, approximately 17,000 domains have been identified hosting second-generation iterations of Coruna and DarkSword. These exploit chains target iPhones running iOS versions 13 through 18.7 and use a combination of vulnerabilities in JavaScriptCore, dyld, ANGLE, and the iOS kernel to achieve remote code execution (RCE), sandbox escape, and privilege escalation.

Coruna, which was first discussed by iVerify last year, is considered a more mature exploit chain that has been developed over several years. It uses watering-hole attacks to compromise victims’ devices, injecting its code into legitimate system processes such as the power daemon and location daemon to evade detection. Coruna’s toolset includes capabilities such as command and control (C2) functionality, allowing attackers to remotely access compromised devices.

DarkSword, on the other hand, is a more recent development that was used in campaigns linked to multiple commercial surveillance vendors and suspected state-sponsored actors. It targets iPhones running iOS versions 18.4 through 18.7 and uses a combination of vulnerabilities to achieve RCE, sandbox escape, and privilege escalation.

What’s alarming is that cybercriminals are not only adopting these exploit chains but also modifying them to improve their effectiveness. Researchers at iVerify have observed new variants with improved jailbreak and virtualization detection functionality, encryption, and Telegram-focused implants. In some cases, threat actors are combining techniques from both frameworks, creating hybrid variants such as “Darkuna” that illustrate the evolving nature of these exploit chains.

The widespread adoption of Coruna and DarkSword poses significant risks to global security, particularly for organizations with mobile devices in use. These exploit chains can be easily deployed by cybercriminals, making it essential for individuals and organizations to stay vigilant and take proactive measures to protect themselves.

In the words of Matthias Frielingsdorf, vice president of research at iVerify, “This is extremely dangerous and extremely easy to proliferate.” With thousands of domains hosting second-generation iterations of these exploit chains, it’s clear that Coruna and DarkSword are becoming increasingly popular among cybercriminals. To mitigate this risk, we recommend that organizations implement robust mobile security measures, including regular software updates, secure browsing habits, and employee education on phishing attacks.

By staying informed about the latest threats and taking proactive steps to protect ourselves, we can minimize the impact of these exploit chains and prevent them from spreading further.


Source: Dark Reading — 2026-08-10