HackMyIP
← Back to News
2026-08-10 Dark Reading

Coruna and DarkSword iOS Exploits Spread to Cybercrime Groups

Zero-DayAPTThreat Intel

Sophisticated iPhone exploit chains previously wielded exclusively by nation-state intelligence agencies are now proliferating across the global cybercrime underground, according to new research. The chains — Coruna and DarkSword — represent some of the most advanced iOS attack tooling ever observed, and their migration to financially motivated threat actors marks a dangerous democratization of mobile surveillance capabilities once reserved for state-level espionage.

Coruna and DarkSword are multi-stage exploit chains that chain zero-day vulnerabilities across WebKit, the iOS kernel, and other critical system components to achieve full device compromise with little or no user interaction, often delivered via iMessage, Safari, or a malicious link. Such chains have historically powered mercenary spyware products such as NSO Group's Pegasus and Intellexa's Predator, sold to vetted government clients for targeted surveillance. Researchers note that the leak, theft, and resale of these chains — frequently through insider access at offensive-security vendors — has now placed comparable capability in the hands of organized ransomware affiliates, surveillance-for-hire firms, and crypto-stealing syndicates. Once deployed, attackers gain persistent access to the device camera, microphone, messages, keychain, and credentials — including any iCloud Keychain secrets stored on the handset.

For ordinary users and corporate mobile fleets, the consequences are immediate. A single successful drive-by exploit can sidestep app sandboxing and on-device encryption, exposing corporate VPN profiles, SSO tokens, and email credentials that fuel broader network intrusions and BEC fraud. Defenders should audit which iOS versions are deployed across the organization, prioritize rapid patching, enable Lockdown Mode for high-risk roles, and monitor for unusual cellular and DNS data flows. Individuals can run a quick privacy checkup to surface suspicious DNS or IP leaks from mobile apps, and verify that no credentials tied to their Apple ID or work accounts have appeared in known infostealer dumps using the email breach checker. Any password stored on a potentially compromised device should be rotated and validated with the password checker to ensure the replacement is strong and unique.

The spread of Coruna and DarkSword signals that the line between APT-grade mobile tooling and mainstream cybercrime has effectively dissolved. Expect exploit chain pricing on underground forums to fall as competition increases — and expect the volume of mobile-borne intrusions to rise in lockstep. Defenders who previously treated iOS exploitation as a theoretical concern should now treat it as an active, recurring threat requiring continuous monitoring.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →