mimile
Back to feed

17,000 domains host Coruna and DarkSword iPhone exploit variants, iVerify finds

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

17,000 domains host Coruna and DarkSword iPhone exploit variants, iVerify finds

More than 17,000 domains are hosting second-generation variants of the Coruna and DarkSword iPhone exploit chains, according to security firm iVerify, as sophisticated tools once limited to nation-states are adopted by common cybercriminals. The spread has continued months after public disclosure, with threat actors improving encryption, persistence mechanisms, and implant capabilities. iVerify and Palo Alto Networks have observed operators combining techniques from both frameworks, informally naming hybrid variants "Darkuna."

Proliferation of Coruna and DarkSword

The Coruna and DarkSword exploit chains, first detailed by Google, iVerify, and Lookout, were previously used in targeted campaigns linked to commercial surveillance vendors and state-sponsored actors in Malaysia, Saudi Arabia, Turkey, and Ukraine. iVerify has now identified approximately 17,000 domains hosting second-generation iterations, a stark contrast to their previous limited deployment. Matthias Frielingsdorf, VP of research at iVerify, warned that an iOS exploit chain can be deployed in five minutes, making it "extremely dangerous and extremely easy to proliferate." Infections have persisted months after initial public disclosures, signaling that criminal groups have fully incorporated the tools into their operations.

Threat Actor Enhancements

After iVerify’s disclosure of Coruna, threat actors modified the framework, with researchers observing new variants featuring improved jailbreak and virtualization detection, upgraded encryption, Telegram-focused implants, and novel persistence mechanisms. These changes demonstrate that cybercriminals are not just reusing the exploits but actively evolving them to evade detection and enhance stealth. Frielingsdorf noted the modifications are "quite a lot" for this version, including updated process-injection targets and stronger anti-analysis functionality.

Convergence of the Frameworks

iVerify and Palo Alto Networks separately noted threat actors employing both Coruna and DarkSword chains, despite their distinct origins. In some instances, operators appear to combine techniques from the two platforms, prompting iVerify to informally label the hybrids "Darkuna." The firm’s telemetry and third-party reporting reveal that some actors have adopted both frameworks, indicating a blurring of the lines between what were once separate nation-state tools. This convergence underscores the rapid commoditization of advanced iOS exploit chains.

What's Next

iVerify and other security firms continue to monitor the evolving threat, with concern that further iterations could integrate even more sophisticated anti-forensic capabilities. It remains unclear whether the original developers — likely nation-state or mercenary groups — will reassert control or if the criminal ecosystem will spawn entirely new branching variants.

1 source

17,000 domains host Coruna and DarkSword iPhone exploit variants, iVerify finds