Two sophisticated iPhone exploit chains named Coruna and DarkSword have escaped the confines of state-sponsored actors and now circulate among organized cybercrime groups worldwide. The exploit chains, built on zero-day vulnerabilities in Apple's iOS, previously served nation-state threat actors with advanced persistent threat capabilities.
Security researchers report that both chains achieve code execution through kernel-level access on targeted iPhones. This level of control allows attackers to bypass Apple's security sandboxing, install persistent backdoors, and extract sensitive data without user detection. The exploits work silently in the background, leaving minimal forensic traces.
Coruna and DarkSword leverage multiple vulnerabilities chained together. Each exploits a separate flaw in iOS components to achieve privilege escalation and escape the application sandbox. Once exploited, a device becomes fully compromised. Attackers gain access to encrypted communications, financial data, location history, and stored credentials.
The proliferation reflects a troubling trend. Previously exclusive cyberweapons developed by intelligence agencies find their way into criminal hands through various vectors. Leaked exploit code, reverse engineering, or insider sales within the security community accelerate distribution.
Apple has released patches for the known vulnerabilities, but devices running older iOS versions remain at risk. Organizations managing large iPhone fleets face urgent pressure to mandate immediate updates. Individual users who delay patching expose themselves to compromise.
For enterprise defenders, detecting these exploit chains presents real challenges. The exploits execute at kernel level, below the visibility of traditional mobile security tools. Behavioral detection relies on identifying unusual device activity, but sophisticated variants minimize detectable patterns.
Law enforcement agencies actively investigate the criminal organizations using these tools. Attribution remains difficult given the exploit's global distribution and the anonymity layers cybercriminals employ.
Apple declined to comment on specific vulnerabilities but emphasized its commitment to rapid patching cycles. The company recommends enabling
