Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals

Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

ThreatVectr Newsdesk· 3 min read
Close-up top-down view of a sleek aluminum laptop keyboard and trackpad on a matte desk surface, soft cool studio lighting casting subtle shadows, a faint abstr
Share

Key points

  • iVerify has tracked approximately 17,000 domains hosting updated versions of two iPhone attack tools, Coruna and DarkSword, as of mid-2026.
  • DarkSword has been active since November 2025, targeting iPhones running iOS 18.4 through 18.7 across Malaysia, Saudi Arabia, Turkey, and Ukraine.
  • Coruna deploys 23 separate software flaws across five attack chains and is estimated to have cost between $30 million and $40 million to build.
  • Apple has patched the flaws behind both tools, but millions of iPhones remain unpatched and exposed.
  • Researchers at Black Hat USA 2026 warned this is the first time nation-state-grade iPhone exploitation has spilled into organised crime at meaningful scale.

Two iPhone attack toolkits that were developed for government spy programmes have escaped into the wider criminal world, and security researchers say the spread is accelerating.

The tools are called Coruna and DarkSword. Each is what researchers call an exploit chain, meaning a sequence of software flaws that, when triggered one after another, gives an attacker full control of a phone. Think of it like a lockpick set that opens several doors in a row, ending with full access to everything inside.

How bad is this, really?

Bad enough that Matthias Frielingsdorf, vice president of research at the mobile security firm iVerify, told an audience at Black Hat USA 2026 last week that this is the first time he has seen tools of this quality move from government use into organised crime at scale. His firm has found roughly 17,000 websites built to deliver the attacks.

"In five minutes, you can deploy an iOS exploit chain," Frielingsdorf said. "This is extremely dangerous and extremely easy to proliferate."

iVerify researchers also spotted criminals mixing techniques from both toolkits to create hybrid versions they informally named "Darkuna," which include new ways to hide from security software and new methods to stay on a phone even after a restart.

What do these tools actually do to your phone?

DarkSword steals, in Frielingsdorf's words, "basically everything." That includes saved passwords (stored in a part of the iPhone called the Keychain), Wi-Fi passwords, iCloud data, photos, notes, and cryptocurrency wallet credentials. It exploits six separate security flaws, including memory corruption bugs CVE-2025-31277, CVE-2025-43529, CVE-2025-43510, and CVE-2025-43520, plus an authentication bypass tracked as CVE-2026-20700 and an ANGLE graphics flaw tracked as CVE-2025-14174. Apple patched DarkSword in April 2026.

Coruna is older. It targets iPhones running iOS 13 through iOS 17.2.1, uses 23 separate flaws across five attack chains, and is believed to have cost $30 million to $40 million to build, originally commissioned by a government contractor. It spreads through watering-hole attacks, where victims simply visit a website that has been quietly rigged to attack their browser. Once inside, the tool hides inside normal iPhone system processes, like the power management service, so it does not look like spy software. Apple patched the underlying flaws in 2023 and 2024.

Tool iOS versions targeted Known flaws used Apple patch date
DarkSword 18.4 to 18.7 6 CVEs April 2026
Coruna 13 to 17.2.1 23 CVEs 2023 to 2024

What should iPhone owners do?

Update your iPhone now. Both toolkits rely on flaws Apple has already fixed. Keeping software current is the single most effective thing an ordinary user can do. Go to Settings, then General, then Software Update.

Also be cautious about websites you visit from unknown links, particularly in text messages or emails you were not expecting. Coruna is specifically designed to attack through the browser, so avoiding unfamiliar links reduces exposure.

If you hold cryptocurrency on your phone, those wallets are a stated target of DarkSword. Consider moving large holdings to a dedicated hardware wallet that is not connected to the internet.

© 2026 Threat Vectr